Vulnerabilities > Microsoft > Windows Vista > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-07-30 CVE-2008-3365 Path Traversal vulnerability in Pixelpost 1.7.1
Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a ..
6.8
2008-06-12 CVE-2008-1441 Improper Input Validation vulnerability in Microsoft products
Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "PGM Malformed Fragment Vulnerability."
network
high complexity
microsoft CWE-20
5.4
2008-06-10 CVE-2008-1581 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Heap-based buffer overflow in Apple QuickTime before 7.5 on Windows allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted packed scanlines in PixData structures in a PICT image.
6.8
2008-04-25 CVE-2008-1932 Numeric Errors vulnerability in Realtek HD Audio Codec Drivers
Integer overflow in Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allows local users to execute arbitrary code via a crafted IOCTL request.
local
low complexity
microsoft realtek CWE-189
6.8
2008-04-25 CVE-2008-1931 Permissions, Privileges, and Access Controls vulnerability in Realtek HD Audio Codec Drivers
Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allow local users to create, write, and read registry keys via a crafted IOCTL request.
local
low complexity
microsoft realtek CWE-264
6.8
2008-04-17 CVE-2008-1026 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Safari 3/3.1
Integer overflow in the PCRE regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to execute arbitrary code via a regular expression with large, nested repetition counts, which triggers a heap-based buffer overflow.
6.8
2008-04-17 CVE-2008-1024 Resource Management Errors vulnerability in Apple Safari 3/3.1
Apple Safari before 3.1.1, when running on Windows XP or Vista, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file download with a crafted file name, which triggers memory corruption.
6.8
2008-03-19 CVE-2008-1001 Cross-Site Scripting vulnerability in Apple Safari
Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1, when running on Windows XP or Vista, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is not properly handled in the error page.
4.3
2007-10-23 CVE-2007-5634 Buffer Errors vulnerability in Almico Speedfan 4.33
Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, does not properly check a buffer during an IOCTL 0x9c402420 call, which allows local users to cause a denial of service (machine crash) and possibly gain privileges via unspecified vectors.
local
low complexity
microsoft almico CWE-119
4.9
2007-09-12 CVE-2007-3036 Permissions, Privileges, and Access Controls vulnerability in Microsoft products
Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain setuid binary files."
6.9