Show filters
152 Total Results
Displaying 71-80 of 152
Sort by:
Attacker Value
Unknown

CVE-2003-0010

Disclosure Date: March 24, 2003 (last updated February 22, 2025)
Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.
0
Attacker Value
Unknown

CVE-2003-0003

Disclosure Date: February 07, 2003 (last updated February 22, 2025)
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
0
Attacker Value
Unknown

CVE-2002-2028

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing.
0
Attacker Value
Unknown

CVE-2002-1712

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.
0
Attacker Value
Unknown

CVE-2002-2401

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs.
0
Attacker Value
Unknown

CVE-2002-1258

Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.
0
Attacker Value
Unknown

CVE-2002-1325

Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."
0
Attacker Value
Unknown

CVE-2002-1257

Disclosure Date: December 23, 2002 (last updated February 22, 2025)
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.
0
Attacker Value
Unknown

CVE-2002-1260

Disclosure Date: December 23, 2002 (last updated February 22, 2025)
The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet.
0
Attacker Value
Unknown

CVE-2002-1184

Disclosure Date: November 12, 2002 (last updated February 22, 2025)
The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.
0