Vulnerabilities > Microsoft > Windows

DATE CVE VULNERABILITY TITLE RISK
2009-09-14 CVE-2009-2804 Numeric Errors vulnerability in Apple mac OS X, mac OS X Server and Safari
Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an image, leading to a heap-based buffer overflow.
6.8
2009-09-08 CVE-2009-3097 Information Exposure vulnerability in HP Performance Insight 5.3
Multiple unspecified vulnerabilities in HP Performance Insight 5.3 on Windows allow attackers to obtain sensitive information via unknown vectors, as demonstrated by certain modules in VulnDisco Pack Professional 8.11.
network
low complexity
hp microsoft CWE-200
7.8
2009-09-08 CVE-2009-3096 Remote Security vulnerability in HP Performance Insight 5.3
Multiple unspecified vulnerabilities in HP Performance Insight 5.3 allow remote attackers to have an unknown impact, related to (1) a "Remote exploit" on Windows platforms, and (2) a "Remote preauthentication exploit" on the Windows Server 2003 SP2 platform, as demonstrated by certain modules in VulnDisco Pack Professional 8.11.
network
low complexity
microsoft hp
critical
10.0
2009-06-26 CVE-2009-1628 Buffer Errors vulnerability in Unisys Business Information Server 10/10.1
Stack-based buffer overflow in mnet.exe in Unisys Business Information Server (BIS) 10 and 10.1 on Windows allows remote attackers to execute arbitrary code via a crafted TCP packet.
network
low complexity
unisys microsoft CWE-119
critical
10.0
2009-06-26 CVE-2009-1394 Buffer Errors vulnerability in Motorola Timbuktu PRO 8.6.5
Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed string over the PlughNTCommand named pipe.
network
microsoft motorola CWE-119
critical
9.3
2009-06-08 CVE-2009-1419 Unspecified vulnerability in HP Discovery&Dependency Mapping Inventory
Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.0.0 through 2.52, 7.50, and 7.51 on Windows allows remote attackers to access DDMI agents via unknown vectors.
network
high complexity
microsoft hp
4.0
2009-06-03 CVE-2008-6820 Configuration vulnerability in IBM DB2 8.0/9.1/9.5
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.
network
low complexity
ibm microsoft CWE-16
critical
10.0
2009-05-14 CVE-2009-0714 Privilege Escalation vulnerability in HP Data Protector Express 3.5/4.0
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers to cause a denial of service (application crash) or read portions of memory via one or more crafted packets.
local
low complexity
microsoft novell redhat suse hp
7.2
2009-05-05 CVE-2009-1522 Unspecified vulnerability in IBM Tivoli Storage Manager Client
The IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspecified man-in-the-middle attacks and read arbitrary files via unknown vectors.
network
ibm microsoft
7.1
2009-04-17 CVE-2008-5518 Path Traversal vulnerability in Apache Geronimo
Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet); the (5) createDB parameter to console/portal/Embedded DB/DB Manager (aka the Embedded DB/DB Manager portlet); or the (6) filename parameter to the createKeystore script in the Security/Keystores portlet.
network
low complexity
apache microsoft CWE-22
critical
9.4