Vulnerabilities > Microsoft > Windows > High

DATE CVE VULNERABILITY TITLE RISK
2009-05-14 CVE-2009-0714 Privilege Escalation vulnerability in HP Data Protector Express 3.5/4.0
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers to cause a denial of service (application crash) or read portions of memory via one or more crafted packets.
local
low complexity
microsoft novell redhat suse hp
7.2
2009-05-05 CVE-2009-1522 Unspecified vulnerability in IBM Tivoli Storage Manager Client
The IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspecified man-in-the-middle attacks and read arbitrary files via unknown vectors.
network
ibm microsoft
7.1
2009-02-19 CVE-2008-6194 Resource Management Errors vulnerability in Microsoft Windows
Memory leak in the DNS server in Microsoft Windows allows remote attackers to cause a denial of service (memory consumption) via DNS packets.
network
low complexity
microsoft CWE-399
7.8
2009-01-15 CVE-2009-0123 Information Exposure vulnerability in Apple Safari
Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for RSS feeds.
7.1
2008-12-03 CVE-2008-5315 Path Traversal vulnerability in Apple Iphone Configuration web Utility 1.0
Directory traversal vulnerability in the web interface in Apple iPhone Configuration Web Utility 1.0 on Windows allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
apple microsoft CWE-22
7.8
2008-11-10 CVE-2008-4820 Information Exposure vulnerability in Adobe Flash Player
Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player 9.0.124.0 and earlier on Windows allows attackers to obtain sensitive information via unknown vectors.
7.1
2008-04-28 CVE-2008-1998 Permissions, Privileges, and Access Controls vulnerability in IBM DB2 8.0/9.1/9.5
The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter.
8.5
2008-03-20 CVE-2008-1402 Resource Management Errors vulnerability in Mg-Soft NET Inspector
MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to cause a (1) denial of service (exception and crash) via a UDP packet to the SNMP Trap Service (MgWTrap3.exe) or (2) denial of service (device freeze or memory consumption) via a malformed request to the Net Inspector Server (niengine).
7.1
2008-03-20 CVE-2008-1363 Permissions, Privileges, and Access Controls vulnerability in VMWare products
VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation of a config.ini file located in an Application Data folder, which can be used for "hijacking the VMX process."
local
low complexity
microsoft vmware CWE-264
7.2
2008-02-29 CVE-2008-0304 Buffer Errors vulnerability in Mozilla Seamonkey and Thunderbird
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.
network
low complexity
linux microsoft mozilla CWE-119
7.5