11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2008-6392
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2008 1 PoC

SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVE-2008-4841
Software Genérico Windows
N/A
UNKNOWN
EPSS
74.6%
2008 3 PoCs

The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008. NOTE: As of 20081210, it is unclear whether this vulnerability is related to a WordPad issue disclosed on 20080925 with a 2008-crash.doc.rar example, but there are insufficient details to be sure.

CVE-2008-1445
Software Genérico Windows
N/A
UNKNOWN
EPSS
57.9%
2008 1 PoC

Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.

CVE-2014-3849
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
10.3%
2014 3 PoCs

The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the i4w_clearuser parameter.

CVE-2008-4473
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
27.5%
2008 1 PoC

Multiple heap-based buffer overflows in Adobe Flash CS3 Professional on Windows and Flash MX 2004 allow remote attackers to execute arbitrary code via an SWF file containing long control parameters.

CVE-2008-6737
Software Genérico Windows
N/A
UNKNOWN
EPSS
5.5%
2008 1 PoC

Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, which causes Crysis to send a disconnect packet that includes unrelated log information.

CVE-2008-5750
Software Genérico Windows
N/A
UNKNOWN
EPSS
18.2%
2008 2 PoCs

Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.

CVE-2008-4324
Software Genérico Windows
N/A
UNKNOWN
EPSS
6.6%
2008 4 PoCs

The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and onmouseup events. NOTE: it was later reported that Firefox 3.0.2 on Mac OS X 10.5 is also affected.

CVE-2008-0948
Software Genérico Windows
N/A
UNKNOWN
EPSS
16.0%
2008 4 PoCs

Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versions before 1.3, when running on systems whose unistd.h does not define the FD_SETSIZE macro, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering a large number of open file descriptors.

CVE-2008-3464
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.3%
2008 2 PoCs

afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability."

CVE-2008-2251
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.8%
2008 1 PoC

Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows Kernel Unhandled Exception Vulnerability." NOTE: according to Microsoft, this is not a duplicate of CVE-2008-4510.

CVE-2008-3493
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.5%
2008 1 PoC

vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application crash) via a crafted frame buffer update packet.

CVE-2008-2246
Software Genérico Windows
N/A
UNKNOWN
EPSS
53.6%
2008 1 PoC

Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.

CVE-2008-0083
Software Genérico Windows
N/A
UNKNOWN
EPSS
59.3%
2008 1 PoC

The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2015-3106
Software Genérico Windows
N/A
UNKNOWN
EPSS
54.6%
2015 1 PoC

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3103 and CVE-2015-3107.

CVE-2008-1084
Software Genérico Windows
N/A
UNKNOWN
EPSS
11.9%
2008 2 PoCs

Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows local users to execute arbitrary code via unknown vectors related to improper input validation. NOTE: it was later reported that one affected function is NtUserFnOUTSTRING in win32k.sys.

CVE-2008-2263
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2008 1 PoC

SQL injection vulnerability in linking.page.php in Automated Link Exchange Portal allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. NOTE: linking.page.php is commonly renamed to link.php, links.php, etc.

CVE-2008-3752
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2008 1 PoC

SQL injection vulnerability in tr.php in YourFreeWorld Ad-Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVE-2008-5903
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.0%
2008 1 PoC

Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via vectors that manipulate the value of the edit_pos structure member.

CVE-2008-5348
Software Genérico Windows
N/A
UNKNOWN
EPSS
12.2%
2008 1 PoC

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier, when using Kerberos authentication, allows remote attackers to cause a denial of service (OS resource consumption) via unknown vectors.