Show filters
80 Total Results
Displaying 61-70 of 80
Sort by:
Attacker Value
Unknown

CVE-2003-0010

Disclosure Date: March 24, 2003 (last updated February 22, 2025)
Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.
0
Attacker Value
Unknown

CVE-2003-0003

Disclosure Date: February 07, 2003 (last updated February 22, 2025)
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
0
Attacker Value
Unknown

CVE-2002-2028

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing.
0
Attacker Value
Unknown

CVE-2002-2401

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs.
0
Attacker Value
Unknown

CVE-2002-1258

Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.
0
Attacker Value
Unknown

CVE-2002-1325

Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."
0
Attacker Value
Unknown

CVE-2002-1257

Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.
0
Attacker Value
Unknown

CVE-2002-1260

Disclosure Date: December 23, 2002 (last updated February 22, 2025)
The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet.
0
Attacker Value
Unknown

CVE-2002-0863

Disclosure Date: October 11, 2002 (last updated February 22, 2025)
Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."
0
Attacker Value
Unknown

CVE-2002-0693

Disclosure Date: October 10, 2002 (last updated February 22, 2025)
Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.
0