Vulnerabilities > Microsoft > Windows XP

DATE CVE VULNERABILITY TITLE RISK
2013-12-11 CVE-2013-3899 Improper Input Validation vulnerability in Microsoft Windows Server 2003 and Windows XP
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate addresses, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
local
low complexity
microsoft CWE-20
7.2
2013-12-11 CVE-2013-3878 Buffer Errors vulnerability in Microsoft Windows Server 2003 and Windows XP
Stack-based buffer overflow in the LRPC client in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges by operating an LRPC server that sends a crafted LPC port message, aka "LRPC Client Buffer Overrun Vulnerability."
6.9
2013-11-28 CVE-2013-5065 Improper Input Validation vulnerability in Microsoft Windows 2003 Server and Windows XP
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.
local
low complexity
microsoft CWE-20
7.2
2013-11-18 CVE-2013-6801 Resource Management Errors vulnerability in Microsoft Word 2003
Microsoft Word 2003 SP2 and SP3 on Windows XP SP3 allows remote attackers to cause a denial of service (CPU consumption) via a malformed .doc file containing an embedded image, as demonstrated by word2003forkbomb.doc, related to a "fork bomb" issue.
network
microsoft CWE-399
7.1
2013-11-18 CVE-2013-3876 Improper Input Validation vulnerability in Microsoft products
DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify server X.509 certificates, which allows man-in-the-middle attackers to spoof servers and read encrypted domain credentials via a crafted certificate.
network
microsoft CWE-20
7.1
2013-11-13 CVE-2013-3940 Integer Overflow OR Wraparound vulnerability in Microsoft products
Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image in a Windows Write (.wri) document, which is not properly handled in WordPad, aka "Graphics Device Interface Integer Overflow Vulnerability."
network
microsoft CWE-190
critical
9.3
2013-11-13 CVE-2013-3869 Improper Input Validation vulnerability in Microsoft products
Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to cause a denial of service (daemon hang) via a web-service request containing a crafted X.509 certificate that is not properly handled during validation, aka "Digital Signatures Vulnerability."
network
low complexity
microsoft CWE-20
5.0
2013-11-12 CVE-2013-3918 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka "InformationCardSigninHelper Vulnerability."
network
microsoft CWE-119
critical
9.3
2013-10-09 CVE-2013-3128 Unspecified vulnerability in Microsoft products
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5, allow remote attackers to execute arbitrary code via a crafted OpenType font (OTF) file, aka "OpenType Font Parsing Vulnerability."
network
microsoft
critical
9.3
2013-09-11 CVE-2013-3863 Buffer Errors vulnerability in Microsoft Windows Server 2003 and Windows XP
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via a crafted OLE object in a file, aka "OLE Property Vulnerability."
network
microsoft CWE-119
critical
9.3