Vulnerabilities > Microsoft > Windows

DATE CVE VULNERABILITY TITLE RISK
2009-11-05 CVE-2009-3872 Multiple Security vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969.
network
sun microsoft
critical
9.3
2009-11-05 CVE-2009-3871 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358.
network
sun microsoft CWE-119
critical
9.3
2009-11-05 CVE-2009-3869 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.
network
sun microsoft CWE-119
critical
9.3
2009-11-05 CVE-2009-3868 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970.
network
sun microsoft CWE-119
critical
9.3
2009-11-05 CVE-2009-3867 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.
network
sun microsoft CWE-119
critical
9.3
2009-11-05 CVE-2009-3864 Multiple Security vulnerability in Sun Java SE November 2009
The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694.
network
low complexity
microsoft sun
7.5
2009-10-22 CVE-2009-1992 Remote Core RDBMS vulnerability in Oracle Database Server 10.1.0.5/10.2.0.4/9.2.0.8
Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
network
low complexity
oracle microsoft
critical
10.0
2009-10-22 CVE-2009-1965 Remote Net Foundation Layer vulnerability in Oracle Database
Unspecified vulnerability in the Net Foundation Layer component in Oracle Database 9.2.0.8 and 10.1.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
5.4
2009-10-02 CVE-2009-3532 SQL Injection vulnerability in Logrover 2.3/2.3.3
Multiple SQL injection vulnerabilities in login.asp (aka the login screen) in LogRover 2.3 and 2.3.3 on Windows allow remote attackers to execute arbitrary SQL commands via the (1) uname and (2) pword parameters.
network
low complexity
logrover microsoft CWE-89
7.5
2009-09-18 CVE-2009-3243 Multiple vulnerability in Wireshark 1.2.0/1.2.1
Unspecified vulnerability in the TLS dissector in Wireshark 1.2.0 and 1.2.1, when running on Windows, allows remote attackers to cause a denial of service (application crash) via unknown vectors related to TLS 1.2 conversations.
network
low complexity
wireshark microsoft
5.0