Show filters
187 Total Results
Displaying 141-150 of 187
Sort by:
Attacker Value
Unknown
CVE-2003-0711
Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.
0
Attacker Value
Unknown
CVE-2003-0604
Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Windows Media Player (WMP) 7 and 8, as running on Internet Explorer and possibly other Microsoft products that process HTML, allows remote attackers to bypass zone restrictions and access or execute arbitrary files via an IFRAME tag pointing to an ASF file whose Content-location contains a File:// URL.
0
Attacker Value
Unknown
CVE-2003-0469
Disclosure Date: August 07, 2003 (last updated February 22, 2025)
Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using a long "align" argument in an HR tag.
0
Attacker Value
Unknown
CVE-2003-0348
Disclosure Date: July 24, 2003 (last updated February 22, 2025)
A certain Microsoft Windows Media Player 9 Series ActiveX control allows remote attackers to view and manipulate the Media Library on the local system via HTML script.
0
Attacker Value
Unknown
CVE-2003-0228
Disclosure Date: May 27, 2003 (last updated February 22, 2025)
Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.
0
Attacker Value
Unknown
CVE-2003-0010
Disclosure Date: March 24, 2003 (last updated February 22, 2025)
Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.
0
Attacker Value
Unknown
CVE-2003-0009
Disclosure Date: March 07, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.
0
Attacker Value
Unknown
CVE-2002-1847
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line argument. NOTE: since the only known attack vector requires command line access, this may not be a vulnerability.
0
Attacker Value
Unknown
CVE-2002-1844
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privileges.
0
Attacker Value
Unknown
CVE-2002-1258
Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.
0