Secunia Logo  


Secunia PSI WorldMap
 
Vulnerability Report: Microsoft Windows XP Home Edition
This vulnerability report for Microsoft Windows XP Home Edition contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Microsoft Windows XP Home Edition then you are more than welcome to contact us.


Table of Contents

1. Product Summary Only

2. Secunia Advisory Statistics (All time)
2.1. Statistics for 2009
2.2. Statistics for 2008
2.3. Statistics for 2007
2.4. Statistics for 2006
2.5. Statistics for 2005
2.6. Statistics for 2004
2.7. Statistics for 2003

3. List of Secunia Advisories (All time)
3.1. List for 2009
3.2. List for 2008
3.3. List for 2007
3.4. List for 2006
3.5. List for 2005
3.6. List for 2004
3.7. List for 2003

4. Send Feedback
 
Vendor, Links, and Unpatched Vulnerabilities

Vendor Microsoft

Product Link N/A

Affected By 246 Secunia advisories
280 Vulnerabilities

Monitor Product Receive alerts for this product

Unpatched 12% (29 of 246 Secunia advisories)

Most Critical Unpatched
The most severe unpatched Secunia advisory affecting Microsoft Windows XP Home Edition, with all vendor patches applied, is rated Highly critical .




246 Secunia Advisories in 2003-2009
Secunia has issued a total of 246 Secunia advisories in 2003-2009 for Microsoft Windows XP Home Edition. Currently, 12% (29 out of 246) are marked as unpatched with the most severe being rated Highly critical

More information about the specific Secunia advisories affecting Microsoft Windows XP Home Edition can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.



Microsoft Windows Indeo Codec Multiple Vulnerabilities
Unpatched. Secunia Advisory 1 of 34 in 2009. 1,113 views.
Release Date:
2009-12-08
Secunia Advisory ID:
SA37592
Solution Status:
Unpatched
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows MS-CHAP Authentication Bypass
Vendor Patch. Secunia Advisory 2 of 34 in 2009. 453 views.
Release Date:
2009-12-08
Secunia Advisory ID:
SA37543
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to bypass certain security restrictions. [Read More]


Microsoft Windows Local Security Authority Subsystem Denial of Service
Vendor Patch. Secunia Advisory 3 of 34 in 2009. 470 views.
Release Date:
2009-12-08
Secunia Advisory ID:
SA37524
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious users to cause a DoS (Denial of Service). [Read More]


Microsoft WordPad / Office Text Converters Integer Overflow Vulnerabilities
Vendor Patch. Secunia Advisory 4 of 34 in 2009. 1,058 views.
Release Date:
2009-12-08
Secunia Advisory ID:
SA37580
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows and Microsoft Office, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Win32k Kernel-Mode Driver Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 5 of 34 in 2009. 6,031 views.
Release Date:
2009-11-10
Secunia Advisory ID:
SA37318
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to compromise a user's system. [Read More]


Microsoft Windows Active Directory Denial of Service
Vendor Patch. Secunia Advisory 6 of 34 in 2009. 1,001 views.
Release Date:
2009-11-10
Secunia Advisory ID:
SA37304
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Products GDI+ Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 7 of 34 in 2009. 9,281 views.
Release Date:
2009-10-14
Secunia Advisory ID:
SA37007
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in various Microsoft products, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Privilege Escalation and Denial of Service
Vendor Patch. Secunia Advisory 8 of 34 in 2009. 1,103 views.
Release Date:
2009-10-14
Secunia Advisory ID:
SA37001
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
DoS
Where:
Local system
Short Description:
Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to potentially gain escalated privileges. [Read More]


Microsoft Local Security Authority Subsystem Denial of Service
Vendor Patch. Secunia Advisory 9 of 34 in 2009. 1,431 views.
Release Date:
2009-10-14
Secunia Advisory ID:
SA37002
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows Media Runtime Code Execution Vulnerability
Vendor Patch. Secunia Advisory 10 of 34 in 2009. 1,195 views.
Release Date:
2009-10-13
Secunia Advisory ID:
SA36938
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Indexing Service ActiveX Control Memory Corruption
Vendor Patch. Secunia Advisory 11 of 34 in 2009. 965 views.
Release Date:
2009-10-13
Secunia Advisory ID:
SA37000
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to potentially compromise a user's system. [Read More]


Microsoft Windows CryptoAPI Two Spoofing Vulnerabilities
Vendor Patch. Secunia Advisory 12 of 34 in 2009. 1,098 views.
Release Date:
2009-10-13
Secunia Advisory ID:
SA36999
Solution Status:
Vendor Patch
Criticality:
Impact:
Spoofing
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to conduct spoofing attacks. [Read More]


Microsoft Windows ActiveX Controls ATL "OleLoadFromStream()" Vulnerability
Vendor Patch. Secunia Advisory 13 of 34 in 2009. 2,311 views.
Release Date:
2009-10-13
Secunia Advisory ID:
SA36997
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system. [Read More]


Windows 2000 / XP TCP/IP Window Size Denial of Service Vulnerabilities
Unpatched. Secunia Advisory 14 of 34 in 2009. 4,521 views.
Release Date:
2009-09-08
Secunia Advisory ID:
SA36597
Solution Status:
Unpatched
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows 2000 and Windows XP, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft JScript Scripting Engine Memory Corruption Vulnerability
Vendor Patch. Secunia Advisory 15 of 34 in 2009. 1,505 views.
Release Date:
2009-09-08
Secunia Advisory ID:
SA36551
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Media Format Two Code Execution Vulnerabilities
Vendor Patch. Secunia Advisory 16 of 34 in 2009. 2,971 views.
Release Date:
2009-09-08
Secunia Advisory ID:
SA36596
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows Media Format, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows DHTML Editing ActiveX Control Vulnerability
Vendor Patch. Secunia Advisory 17 of 34 in 2009. 1,404 views.
Release Date:
2009-09-08
Secunia Advisory ID:
SA36592
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows AVI Media File Parsing Vulnerabilities
Vendor Patch. Secunia Advisory 18 of 34 in 2009. 1,607 views.
Release Date:
2009-08-11
Secunia Advisory ID:
SA36206
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Workstation Service Memory Corruption
Vendor Patch. Secunia Advisory 19 of 34 in 2009. 1,468 views.
Release Date:
2009-08-11
Secunia Advisory ID:
SA36220
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious users to compromise a vulnerable system. [Read More]


Microsoft Windows Message Queuing Service Privilege Escalation
Vendor Patch. Secunia Advisory 20 of 34 in 2009. 1,575 views.
Release Date:
2009-08-11
Secunia Advisory ID:
SA36214
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Windows Various Components ATL Vulnerabilities
Vendor Patch. Secunia Advisory 21 of 34 in 2009. 8,036 views.
Release Date:
2009-08-11
Secunia Advisory ID:
SA36187
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
System access
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in various Windows components, which can be exploited by malicious people to bypass security features or compromise a user's system. [Read More]


Microsoft Remote Desktop Connection Two Vulnerabilities
Vendor Patch. Secunia Advisory 22 of 34 in 2009. 6,098 views.
Release Date:
2009-08-11
Secunia Advisory ID:
SA36229
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows and Microsoft Remote Desktop Connection Client for Mac, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Telnet NTLM Credential Reflection Vulnerability
Vendor Patch. Secunia Advisory 23 of 34 in 2009. 1,633 views.
Release Date:
2009-08-11
Secunia Advisory ID:
SA36222
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Windows Embedded OpenType Font Engine Two Vulnerabilities
Vendor Patch. Secunia Advisory 24 of 34 in 2009. 6,962 views.
Release Date:
2009-07-14
Secunia Advisory ID:
SA35773
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft DirectShow Streaming Video ActiveX Control Vulnerabilities
Vendor Patch. Secunia Advisory 25 of 34 in 2009. 14,503 views.
Release Date:
2009-07-06
Secunia Advisory ID:
SA35683
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Print Spooler Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 26 of 34 in 2009. 3,102 views.
Release Date:
2009-06-09
Secunia Advisory ID:
SA35365
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
Exposure of sensitive information
System access
Where:
From local network
Short Description:
Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to disclose sensitive information, and by malicious users and malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Kernel Privilege Escalation Vulnerabilities
Vendor Patch. Secunia Advisory 27 of 34 in 2009. 2,338 views.
Release Date:
2009-06-09
Secunia Advisory ID:
SA35372
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Windows RPC Marshalling Engine Vulnerability
Vendor Patch. Secunia Advisory 28 of 34 in 2009. 4,334 views.
Release Date:
2009-06-09
Secunia Advisory ID:
SA35373
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to potentially compromise a vulnerable system. [Read More]


Microsoft Windows "SystemParametersInfo()" Privilege Escalation
Vendor Patch. Secunia Advisory 29 of 34 in 2009. 2,540 views.
Release Date:
2009-06-03
Secunia Advisory ID:
SA35323
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft DirectShow QuickTime Parsing Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 30 of 34 in 2009. 8,296 views.
Release Date:
2009-05-29
Secunia Advisory ID:
SA35268
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in Microsoft DirectX, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows HTTP Services Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 31 of 34 in 2009. 7,832 views.
Release Date:
2009-04-14
Secunia Advisory ID:
SA34677
Solution Status:
Vendor Patch
Criticality:
Impact:
Spoofing
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to conduct spoofing attacks or compromise a user's system. [Read More]


Microsoft DirectShow MJPEG Decompression Vulnerability
Vendor Patch. Secunia Advisory 32 of 34 in 2009. 3,777 views.
Release Date:
2009-04-14
Secunia Advisory ID:
SA34665
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft DirectX, which can be exploited by malicious people to potentially compromise a user's system. [Read More]


Microsoft Windows SChannel Authentication Bypass
Vendor Patch. Secunia Advisory 33 of 34 in 2009. 6,500 views.
Release Date:
2009-03-10
Secunia Advisory ID:
SA34215
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to bypass certain security mechanisms. [Read More]


Microsoft Windows Multiple Kernel Vulnerabilities
Vendor Patch. Secunia Advisory 34 of 34 in 2009. 5,361 views.
Release Date:
2009-03-10
Secunia Advisory ID:
SA34117
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
System access
Where:
From remote
Short Description:
Three vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to potentially compromise a user's system. [Read More]


Microsoft Windows GDI Image Parsing Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 30 in 2008. 8,994 views.
Release Date:
2008-12-09
Secunia Advisory ID:
SA33020
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to potentially compromise a vulnerable system. [Read More]


Microsoft Windows WordPad / Office Text Converters Vulnerabilities
Vendor Patch. Secunia Advisory 2 of 30 in 2008. 9,924 views.
Release Date:
2008-12-09
Secunia Advisory ID:
SA32997
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in Microsoft Windows and Microsoft Office, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows SMB Authentication Credential Replay Vulnerability
Vendor Patch. Secunia Advisory 3 of 30 in 2008. 8,116 views.
Release Date:
2008-11-11
Secunia Advisory ID:
SA32633
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Spoofing
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to bypass certain security features. [Read More]


Microsoft Windows Path Canonicalisation Vulnerability
Vendor Patch. Secunia Advisory 4 of 30 in 2008. 23,071 views.
Release Date:
2008-10-23
Secunia Advisory ID:
SA32326
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows SMB Buffer Underflow Vulnerability
Vendor Patch. Secunia Advisory 5 of 30 in 2008. 4,794 views.
Release Date:
2008-10-14
Secunia Advisory ID:
SA32249
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows IIS IPP Service Integer Overflow Vulnerability
Vendor Patch. Secunia Advisory 6 of 30 in 2008. 6,727 views.
Release Date:
2008-10-14
Secunia Advisory ID:
SA32248
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious users to compromise a vulnerable system. [Read More]


Microsoft Windows Ancillary Function Driver Privilege Escalation
Vendor Patch. Secunia Advisory 7 of 30 in 2008. 4,204 views.
Release Date:
2008-10-14
Secunia Advisory ID:
SA32261
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Windows Privilege Escalation Vulnerabilities
Vendor Patch. Secunia Advisory 8 of 30 in 2008. 4,103 views.
Release Date:
2008-10-14
Secunia Advisory ID:
SA32247
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
DoS
Where:
Local system
Short Description:
Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or gain escalated privileges. [Read More]


Microsoft Windows Virtual Address Descriptor Privilege Escalation
Vendor Patch. Secunia Advisory 9 of 30 in 2008. 3,861 views.
Release Date:
2008-10-14
Secunia Advisory ID:
SA32251
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Windows SMB Packet Handling Vulnerabilities
Vendor Patch. Secunia Advisory 10 of 30 in 2008. 9,553 views.
Release Date:
2008-09-16
Secunia Advisory ID:
SA31883
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
Three vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system. [Read More]


Microsoft Windows "IopfCompleteRequest" Integer Overflow Vulnerability
Unpatched. Secunia Advisory 11 of 30 in 2008. 6,570 views.
Release Date:
2008-09-10
Secunia Advisory ID:
SA31824
Solution Status:
Unpatched
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Ruben Santamarta has reported a vulnerability in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Products GDI+ Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 12 of 30 in 2008. 13,460 views.
Release Date:
2008-09-09
Secunia Advisory ID:
SA31675
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in various Microsoft products, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Event System Privilege Escalation Vulnerabilities
Vendor Patch. Secunia Advisory 13 of 30 in 2008. 5,990 views.
Release Date:
2008-08-12
Secunia Advisory ID:
SA31417
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Windows Color Management System Buffer Overflow
Vendor Patch. Secunia Advisory 14 of 30 in 2008. 8,193 views.
Release Date:
2008-08-12
Secunia Advisory ID:
SA31385
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows DNS Spoofing Vulnerabilities
Vendor Patch. Secunia Advisory 15 of 30 in 2008. 8,299 views.
Release Date:
2008-07-08
Secunia Advisory ID:
SA30925
Solution Status:
Vendor Patch
Criticality:
Impact:
Spoofing
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to poison the DNS cache. [Read More]


Microsoft Windows Pragmatic General Multicast Denial of Service
Vendor Patch. Secunia Advisory 16 of 30 in 2008. 6,605 views.
Release Date:
2008-06-10
Secunia Advisory ID:
SA30587
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows Speech Recognition Security Issue
Vendor Patch. Secunia Advisory 17 of 30 in 2008. 6,781 views.
Release Date:
2008-06-10
Secunia Advisory ID:
SA30578
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A security issue has been reported in Microsoft Windows, which potentially can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Bluetooth SDP Packet Processing Vulnerability
Vendor Patch. Secunia Advisory 18 of 30 in 2008. 8,006 views.
Release Date:
2008-06-10
Secunia Advisory ID:
SA30051
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft DirectX MJPEG/SAMI File Processing Vulnerabilities
Vendor Patch. Secunia Advisory 19 of 30 in 2008. 8,345 views.
Release Date:
2008-06-10
Secunia Advisory ID:
SA30579
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft DirectX, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows XP I2O Utility Filter Driver Privilege Escalation
Vendor Patch. Secunia Advisory 20 of 30 in 2008. 9,731 views.
Release Date:
2008-05-13
Secunia Advisory ID:
SA30203
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Microsoft Windows XP, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft VBScript/JScript Script Decoding Buffer Overflow
Vendor Patch. Secunia Advisory 21 of 30 in 2008. 9,319 views.
Release Date:
2008-04-08
Secunia Advisory ID:
SA29712
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Kernel Privilege Escalation Vulnerability
Vendor Patch. Secunia Advisory 22 of 30 in 2008. 8,510 views.
Release Date:
2008-04-08
Secunia Advisory ID:
SA29720
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Windows hxvz.dll ActiveX Control Memory Corruption
Vendor Patch. Secunia Advisory 23 of 30 in 2008. 9,193 views.
Release Date:
2008-04-08
Secunia Advisory ID:
SA29714
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows GDI Image Parsing Buffer Overflows
Vendor Patch. Secunia Advisory 24 of 30 in 2008. 8,925 views.
Release Date:
2008-04-08
Secunia Advisory ID:
SA29704
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows DNS Client Predictable Transaction ID Vulnerability
Vendor Patch. Secunia Advisory 25 of 30 in 2008. 8,202 views.
Release Date:
2008-04-08
Secunia Advisory ID:
SA29696
Solution Status:
Vendor Patch
Criticality:
Impact:
Spoofing
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to poison the DNS cache. [Read More]


Microsoft Windows "NoDriveTypeAutoRun" Security Issue
Vendor Patch. Secunia Advisory 26 of 30 in 2008. 14,937 views.
Release Date:
2008-03-21
Secunia Advisory ID:
SA29458
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
Local system
Short Description:
CERT/CC has reported a security issue in Windows, which can be exploited by malicious people to bypass certain security settings. [Read More]


Microsoft WebDAV Mini-Redirector Pathname Buffer Overflow
Vendor Patch. Secunia Advisory 27 of 30 in 2008. 9,787 views.
Release Date:
2008-02-12
Secunia Advisory ID:
SA28894
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows OLE Automation Memory Corruption
Vendor Patch. Secunia Advisory 28 of 30 in 2008. 10,104 views.
Release Date:
2008-02-12
Secunia Advisory ID:
SA28902
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows LSASS Privilege Escalation Vulnerability
Vendor Patch. Secunia Advisory 29 of 30 in 2008. 11,633 views.
Release Date:
2008-01-08
Secunia Advisory ID:
SA28341
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Windows TCP/IP Implementation Vulnerabilities
Vendor Patch. Secunia Advisory 30 of 30 in 2008. 18,280 views.
Release Date:
2008-01-08
Secunia Advisory ID:
SA28297
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system. [Read More]


Windows Media Format Runtime ASF Parsing Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 28 in 2007. 14,318 views.
Release Date:
2007-12-11
Secunia Advisory ID:
SA28034
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
IBM X-Force has reported four vulnerabilities in Windows Media Format Runtime / Windows Media Services, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Message Queuing Privilege Escalation
Vendor Patch. Secunia Advisory 2 of 28 in 2007. 9,233 views.
Release Date:
2007-12-11
Secunia Advisory ID:
SA28011
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft DirectX SAMI/WAV/AVI File Parsing Vulnerabilities
Vendor Patch. Secunia Advisory 3 of 28 in 2007. 13,566 views.
Release Date:
2007-12-11
Secunia Advisory ID:
SA28010
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft DirectX, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Web Proxy Auto-Discovery Feature Security Issue
Vendor Workaround. Secunia Advisory 4 of 28 in 2007. 17,975 views.
Release Date:
2007-12-04
Secunia Advisory ID:
SA27901
Solution Status:
Vendor Workaround
Criticality:
Impact:
Security Bypass
Exposure of sensitive information
Where:
From remote
Short Description:
A security issue has been reported in Microsoft's Web Proxy Auto-Discovery (WPAD) feature, which can be exploited by malicious people to conduct man-in-the-middle (MITM) attacks. [Read More]


Macrovision SafeDisc secdrv.sys Privilege Escalation
Vendor Patch. Secunia Advisory 5 of 28 in 2007. 13,424 views.
Release Date:
2007-10-23
Secunia Advisory ID:
SA27285
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Macrovision SafeDisc, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Windows Kodak Image Viewer Code Execution
Vendor Patch. Secunia Advisory 6 of 28 in 2007. 15,349 views.
Release Date:
2007-10-09
Secunia Advisory ID:
SA27092
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows RPC Authentication Denial of Service
Vendor Patch. Secunia Advisory 7 of 28 in 2007. 11,665 views.
Release Date:
2007-10-09
Secunia Advisory ID:
SA27134
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows NNTP Response Handling Buffer Overflow
Vendor Patch. Secunia Advisory 8 of 28 in 2007. 14,085 views.
Release Date:
2007-10-09
Secunia Advisory ID:
SA27112
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
VeriSign iDefense Labs has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Vector Markup Language Buffer Overflow
Vendor Patch. Secunia Advisory 9 of 28 in 2007. 14,277 views.
Release Date:
2007-08-14
Secunia Advisory ID:
SA26409
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Windows Graphics Rendering Engine Image Handling Vulnerability
Vendor Patch. Secunia Advisory 10 of 28 in 2007. 11,576 views.
Release Date:
2007-08-14
Secunia Advisory ID:
SA26423
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which potentially can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows URI Handling Command Execution Vulnerability
Vendor Patch. Secunia Advisory 11 of 28 in 2007. 67,825 views.
Release Date:
2007-07-26
Secunia Advisory ID:
SA26201
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Win32 API Code Execution Vulnerability
Vendor Patch. Secunia Advisory 12 of 28 in 2007. 16,739 views.
Release Date:
2007-06-12
Secunia Advisory ID:
SA25640
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges or by malicious people to compromise a user's system. [Read More]


Microsoft Outlook Express and Windows Mail Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 13 of 28 in 2007. 22,181 views.
Release Date:
2007-06-12
Secunia Advisory ID:
SA25639
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Exposure of sensitive information
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Microsoft Outlook Express and Windows Mail, which can be exploited by malicious people to disclose sensitive information and compromise a user's system. [Read More]


Windows Secure Channel Digital Signature Parsing Vulnerability
Vendor Patch. Secunia Advisory 14 of 28 in 2007. 14,766 views.
Release Date:
2007-06-12
Secunia Advisory ID:
SA25620
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system. [Read More]


Microsoft Windows Kernel Mapped Memory Insecure Permissions
Vendor Patch. Secunia Advisory 15 of 28 in 2007. 11,924 views.
Release Date:
2007-04-10
Secunia Advisory ID:
SA24834
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
eEye Digital Security has reported a vulnerability in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Windows XP UPnP Memory Corruption Vulnerability
Vendor Patch. Secunia Advisory 16 of 28 in 2007. 12,602 views.
Release Date:
2007-04-10
Secunia Advisory ID:
SA24822
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Agent URL Parsing Memory Corruption Vulnerability
Vendor Patch. Secunia Advisory 17 of 28 in 2007. 16,511 views.
Release Date:
2007-04-10
Secunia Advisory ID:
SA22896
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Secunia Research has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Animated Cursor Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 18 of 28 in 2007. 83,903 views.
Release Date:
2007-03-30
Secunia Advisory ID:
SA24659
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows NDISTAPI.SYS Denial of Service
Partial Fix. Secunia Advisory 19 of 28 in 2007. 11,227 views.
Release Date:
2007-03-20
Secunia Advisory ID:
SA24598
Solution Status:
Partial Fix
Criticality:
Impact:
DoS
Where:
Local system
Short Description:
Rubén Santamarta has reported a vulnerability in Microsoft Windows, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]


Microsoft Windows Directory Monitoring Information Disclosure Weakness
Unpatched. Secunia Advisory 20 of 28 in 2007. 16,437 views.
Release Date:
2007-02-23
Secunia Advisory ID:
SA24245
Solution Status:
Unpatched
Criticality:
Impact:
Exposure of sensitive information
Exposure of system information
Where:
Local system
Short Description:
3APA3A has discovered a weakness in Microsoft Windows, which can be exploited by malicious, local users to gain knowledge of certain information. [Read More]


Microsoft RichEdit OLE Dialog Memory Corruption Vulnerability
Vendor Patch. Secunia Advisory 21 of 28 in 2007. 13,832 views.
Release Date:
2007-02-13
Secunia Advisory ID:
SA24152
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows and Microsoft Office, which can be exploited by malicious people to compromise a users system. [Read More]


Microsoft MFC OLE Dialog Memory Corruption Vulnerability
Vendor Patch. Secunia Advisory 22 of 28 in 2007. 12,965 views.
Release Date:
2007-02-13
Secunia Advisory ID:
SA24150
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows and Visual Studio, which can be exploited by malicious people to compromise a users system. [Read More]


Microsoft Windows OLE Dialog Memory Corruption Vulnerability
Vendor Patch. Secunia Advisory 23 of 28 in 2007. 10,872 views.
Release Date:
2007-02-13
Secunia Advisory ID:
SA24147
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Image Aquisition Service Privilege Escalation
Vendor Patch. Secunia Advisory 24 of 28 in 2007. 12,698 views.
Release Date:
2007-02-13
Secunia Advisory ID:
SA24132
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Microsoft Windows XP, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft MDAC ADODB.Connection ActiveX Control Vulnerability
Vendor Patch. Secunia Advisory 25 of 28 in 2007. 19,525 views.
Release Date:
2007-02-13
Secunia Advisory ID:
SA22452
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Yag Kohha has reported a vulnerability in Microsoft Data Access Components, which potentially can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows HTML Help ActiveX Control Vulnerability
Vendor Patch. Secunia Advisory 26 of 28 in 2007. 13,001 views.
Release Date:
2007-02-13
Secunia Advisory ID:
SA24136
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft XML Core Services Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 27 of 28 in 2007. 51,482 views.
Release Date:
2007-01-09
Secunia Advisory ID:
SA23655
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
DoS
System access
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in Microsoft XML Core Services, which can be exploited by malicious people to gain knowledge of sensitive information or potentially compromise a user's system. [Read More]


Microsoft Windows Vector Markup Language Vulnerabilities
Vendor Patch. Secunia Advisory 28 of 28 in 2007. 34,613 views.
Release Date:
2007-01-09
Secunia Advisory ID:
SA23677
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system [Read More]


Microsoft Windows CSRSS Information Disclosure Vulnerability
Vendor Patch. Secunia Advisory 1 of 46 in 2006. 16,231 views.
Release Date:
2006-12-28
Secunia Advisory ID:
SA23491
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Privilege escalation
DoS
Where:
Local system
Short Description:
Rubén Santamarta has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or gain knowledge of sensitive information. [Read More]


Windows Workstation Service NetrWkstaUserEnum Denial of Service
Unpatched. Secunia Advisory 2 of 46 in 2006. 19,850 views.
Release Date:
2006-12-26
Secunia Advisory ID:
SA23487
Solution Status:
Unpatched
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
h07 has discovered a weakness in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows CSRSS MsgBox Memory Corruption Vulnerability
Vendor Patch. Secunia Advisory 3 of 46 in 2006. 30,151 views.
Release Date:
2006-12-22
Secunia Advisory ID:
SA23448
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Outlook Express Address Book Contact Record Vulnerability
Vendor Patch. Secunia Advisory 4 of 46 in 2006. 13,210 views.
Release Date:
2006-12-12
Secunia Advisory ID:
SA23311
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Outlook Express, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows File Manifest Privilege Escalation Vulnerability
Vendor Patch. Secunia Advisory 5 of 46 in 2006. 11,603 views.
Release Date:
2006-12-12
Secunia Advisory ID:
SA23308
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Windows SNMP Service GetBulkRequest Memory Corruption
Vendor Patch. Secunia Advisory 6 of 46 in 2006. 15,864 views.
Release Date:
2006-12-12
Secunia Advisory ID:
SA23307
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]


Windows Media Format Runtime ASX/ASF Parsing Vulnerabilities
Vendor Patch. Secunia Advisory 7 of 46 in 2006. 18,952 views.
Release Date:
2006-12-08
Secunia Advisory ID:
SA22971
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Windows Media Format Runtime, which potentially can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Client Service for Netware Vulnerabilities
Vendor Patch. Secunia Advisory 8 of 46 in 2006. 19,352 views.
Release Date:
2006-11-14
Secunia Advisory ID:
SA22866
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system. [Read More]


Microsoft Windows Agent ActiveX Control Buffer Overflow
Vendor Patch. Secunia Advisory 9 of 46 in 2006. 18,679 views.
Release Date:
2006-11-14
Secunia Advisory ID:
SA22878
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Workstation Service Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 10 of 46 in 2006. 15,551 views.
Release Date:
2006-11-14
Secunia Advisory ID:
SA22883
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
eEye Digital Security has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Flash Player Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 11 of 46 in 2006. 23,304 views.
Release Date:
2006-11-14
Secunia Advisory ID:
SA22882
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
System access
Where:
From remote
Short Description:
Microsoft has acknowledged some vulnerabilities in Windows XP, which can be exploited by malicious people to bypass certain security restrictions or compromise a user's system. [Read More]


Microsoft Windows GDI Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 12 of 46 in 2006. 20,955 views.
Release Date:
2006-11-06
Secunia Advisory ID:
SA22668
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
DoS
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system. [Read More]


Microsoft XMLHTTP ActiveX Control Code Execution Vulnerability
Vendor Patch. Secunia Advisory 13 of 46 in 2006. 72,739 views.
Release Date:
2006-11-04
Secunia Advisory ID:
SA22687
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been discovered in Microsoft XML Core Services, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Internet Connection Sharing Denial of Service
Unpatched. Secunia Advisory 14 of 46 in 2006. 22,895 views.
Release Date:
2006-10-30
Secunia Advisory ID:
SA22592
Solution Status:
Unpatched
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
h07 has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows Object Packager Dialog Spoofing Vulnerability
Vendor Patch. Secunia Advisory 15 of 46 in 2006. 10,211 views.
Release Date:
2006-10-10
Secunia Advisory ID:
SA20717
Solution Status:
Vendor Patch
Criticality:
Impact:
Spoofing
System access
Where:
From remote
Short Description:
Secunia Research has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious people to conduct spoofing attacks. [Read More]


Microsoft Windows Multiple IPv6 Denial of Service Vulnerabilities
Vendor Patch. Secunia Advisory 16 of 46 in 2006. 12,551 views.
Release Date:
2006-10-10
Secunia Advisory ID:
SA22341
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Three vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows Shell Code Execution Vulnerability
Vendor Patch. Secunia Advisory 17 of 46 in 2006. 37,933 views.
Release Date:
2006-09-28
Secunia Advisory ID:
SA22159
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
H D Moore has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Vector Graphics Rendering Library Buffer Overflow
Vendor Patch. Secunia Advisory 18 of 46 in 2006. 68,458 views.
Release Date:
2006-09-19
Secunia Advisory ID:
SA21989
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Indexing Service Cross-Site Scripting
Vendor Patch. Secunia Advisory 19 of 46 in 2006. 13,384 views.
Release Date:
2006-09-12
Secunia Advisory ID:
SA21861
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Eiji James Yoshida has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to conduct cross-site scripting attacks. [Read More]


Microsoft Windows Pragmatic General Multicast Code Execution
Vendor Patch. Secunia Advisory 20 of 46 in 2006. 14,436 views.
Release Date:
2006-09-12
Secunia Advisory ID:
SA21851
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows XP, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Windows Server Service Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 21 of 46 in 2006. 19,405 views.
Release Date:
2006-08-08
Secunia Advisory ID:
SA21388
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Two Vulnerabilities
Vendor Patch. Secunia Advisory 22 of 46 in 2006. 13,600 views.
Release Date:
2006-08-08
Secunia Advisory ID:
SA21417
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to compromise a vulnerable system. [Read More]


Windows DNS Resolution Code Execution Vulnerabilities
Vendor Patch. Secunia Advisory 23 of 46 in 2006. 17,548 views.
Release Date:
2006-08-08
Secunia Advisory ID:
SA21394
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows WMF File Handling Denial of Service
Unpatched. Secunia Advisory 24 of 46 in 2006. 14,234 views.
Release Date:
2006-08-07
Secunia Advisory ID:
SA21377
Solution Status:
Unpatched
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
cyanid-E has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows Server Service DoS and Privilege Escalation
Vendor Patch. Secunia Advisory 25 of 46 in 2006. 17,526 views.
Release Date:
2006-07-31
Secunia Advisory ID:
SA21276
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
DoS
Where:
From local network
Short Description:
Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows Server Service Two Vulnerabilities
Vendor Patch. Secunia Advisory 26 of 46 in 2006. 15,332 views.
Release Date:
2006-07-11
Secunia Advisory ID:
SA21007
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
System access
Where:
From local network
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to expose sensitive information and compromise a vulnerable system. [Read More]


Windows DHCP Client Service Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 27 of 46 in 2006. 15,010 views.
Release Date:
2006-07-11
Secunia Advisory ID:
SA21010
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
Cybsec Security Systems has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Windows HTML Help ActiveX Control Memory Corruption
Vendor Patch. Secunia Advisory 28 of 46 in 2006. 26,804 views.
Release Date:
2006-07-04
Secunia Advisory ID:
SA20906
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Internet Explorer Information Disclosure and HTA Application Execution
Vendor Patch. Secunia Advisory 29 of 46 in 2006. 29,581 views.
Release Date:
2006-06-27
Secunia Advisory ID:
SA20825
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
System access
Where:
From remote
Short Description:
Plebo Aesdi Nael has discovered two vulnerabilities in Microsoft Windows, which can be exploited by malicious people to disclose potentially sensitive information and potentially compromise a user's system. [Read More]


Microsoft Windows Hyperlink Object Library Vulnerabilities
Vendor Patch. Secunia Advisory 30 of 46 in 2006. 41,928 views.
Release Date:
2006-06-20
Secunia Advisory ID:
SA20748
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft JScript Memory Corruption Vulnerability
Vendor Patch. Secunia Advisory 31 of 46 in 2006. 13,482 views.
Release Date:
2006-06-13
Secunia Advisory ID:
SA20620
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows TCP/IP Protocol Driver Buffer Overflow
Vendor Patch. Secunia Advisory 32 of 46 in 2006. 23,606 views.
Release Date:
2006-06-13
Secunia Advisory ID:
SA20639
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system. [Read More]


Microsoft Windows ART Image Handling Buffer Overflow
Vendor Patch. Secunia Advisory 33 of 46 in 2006. 13,506 views.
Release Date:
2006-06-13
Secunia Advisory ID:
SA20605
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Windows SMB Denial of Service and Privilege Escalation
Vendor Patch. Secunia Advisory 34 of 46 in 2006. 12,004 views.
Release Date:
2006-06-13
Secunia Advisory ID:
SA20635
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
DoS
Where:
Local system
Short Description:
Ruben Santamarta has reported two vulnerabilities in Microsoft Windows, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and gain escalated privileges. [Read More]


Microsoft Windows Routing and Remote Access Vulnerabilities
Vendor Patch. Secunia Advisory 35 of 46 in 2006. 18,938 views.
Release Date:
2006-06-13
Secunia Advisory ID:
SA20630
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people or users to compromise a vulnerable system. [Read More]


Microsoft Windows "mhtml:" URI Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 36 of 46 in 2006. 22,948 views.
Release Date:
2006-06-01
Secunia Advisory ID:
SA20384
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mr.Niega has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows "itss.dll" Heap Corruption Vulnerability
Unpatched. Secunia Advisory 37 of 46 in 2006. 17,444 views.
Release Date:
2006-05-10
Secunia Advisory ID:
SA20061
Solution Status:
Unpatched
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Rubén Santamarta has discovered a vulnerability in Microsoft Windows, which potentially can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Distributed Transaction Coordinator Two Vulnerabilities
Vendor Patch. Secunia Advisory 38 of 46 in 2006. 37,244 views.
Release Date:
2006-05-09
Secunia Advisory ID:
SA20000
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system. [Read More]


Microsoft Windows Flash Player Code Execution Vulnerabilities
Vendor Patch. Secunia Advisory 39 of 46 in 2006. 19,730 views.
Release Date:
2006-05-09
Secunia Advisory ID:
SA20045
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Explorer COM Object Handling Vulnerability
Vendor Patch. Secunia Advisory 40 of 46 in 2006. 16,980 views.
Release Date:
2006-04-11
Secunia Advisory ID:
SA19606
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows / Office Korean Input Method Editor Vulnerability
Vendor Patch. Secunia Advisory 41 of 46 in 2006. 17,632 views.
Release Date:
2006-02-14
Secunia Advisory ID:
SA18859
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
Ryan Lee has reported a vulnerability in various Microsoft products, which can be exploited by malicious people to gain escalated privileges or compromise a vulnerable system. [Read More]


Windows Media Player Plug-in EMBED Element Buffer Overflow
Vendor Patch. Secunia Advisory 42 of 46 in 2006. 25,281 views.
Release Date:
2006-02-14
Secunia Advisory ID:
SA18852
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Windows Media Player plug-in, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Web Client Service Vulnerability
Vendor Patch. Secunia Advisory 43 of 46 in 2006. 13,332 views.
Release Date:
2006-02-14
Secunia Advisory ID:
SA18857
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Windows IGMP Denial of Service Vulnerability
Vendor Patch. Secunia Advisory 44 of 46 in 2006. 17,486 views.
Release Date:
2006-02-14
Secunia Advisory ID:
SA18853
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Windows Insecure Service Permissions Privilege Escalation
Vendor Patch. Secunia Advisory 45 of 46 in 2006. 18,638 views.
Release Date:
2006-02-08
Secunia Advisory ID:
SA18756
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Sudhakar Govindavajhala and Andrew W. Appel have reported some security issues in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Windows Embedded Web Fonts Code Execution Vulnerability
Vendor Patch. Secunia Advisory 46 of 46 in 2006. 18,401 views.
Release Date:
2006-01-10
Secunia Advisory ID:
SA18365
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows WMF "SETABORTPROC" Arbitrary Code Execution
Vendor Patch. Secunia Advisory 1 of 36 in 2005. 167,990 views.
Release Date:
2005-12-28
Secunia Advisory ID:
SA18255
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows UPnP GetDeviceList Denial of Service
Unpatched. Secunia Advisory 2 of 36 in 2005. 19,236 views.
Release Date:
2005-11-17
Secunia Advisory ID:
SA17595
Solution Status:
Unpatched
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
Winny Thomas has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows WMF/EMF File Rendering Arbitrary Code Execution
Vendor Patch. Secunia Advisory 3 of 36 in 2005. 27,678 views.
Release Date:
2005-11-08
Secunia Advisory ID:
SA17498
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Client Service for NetWare Buffer Overflow
Vendor Patch. Secunia Advisory 4 of 36 in 2005. 15,541 views.
Release Date:
2005-10-11
Secunia Advisory ID:
SA17165
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious users, or by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Plug-and-Play Service Buffer Overflows
Vendor Patch. Secunia Advisory 5 of 36 in 2005. 15,586 views.
Release Date:
2005-10-11
Secunia Advisory ID:
SA17166
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
System access
Where:
From local network
Short Description:
eEye Digital Security has reported some vulnerabilities in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges, or by malicious users to compromise a vulnerable system. [Read More]


Microsoft Windows DirectShow AVI Handling Vulnerability
Vendor Patch. Secunia Advisory 6 of 36 in 2005. 20,669 views.
Release Date:
2005-10-11
Secunia Advisory ID:
SA17160
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
eEye Digital Security has been reported a vulnerability in Microsoft Windows DirectShow, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Shell and Web View Three Vulnerabilities
Vendor Patch. Secunia Advisory 7 of 36 in 2005. 15,284 views.
Release Date:
2005-10-11
Secunia Advisory ID:
SA17168
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Three vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows MSDTC and COM+ Vulnerabilities
Vendor Patch. Secunia Advisory 8 of 36 in 2005. 24,513 views.
Release Date:
2005-10-11
Secunia Advisory ID:
SA17161
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
DoS
System access
Where:
From local network
Short Description:
Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges, or by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system. [Read More]


Microsoft Collaboration Data Objects Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 9 of 36 in 2005. 17,306 views.
Release Date:
2005-10-11
Secunia Advisory ID:
SA17167
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Gary O'leary-Steele has reported a vulnerability in Microsoft Windows and Microsoft Exchange 2000 Server, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows FTP Client Filename Validation Vulnerability
Vendor Patch. Secunia Advisory 10 of 36 in 2005. 23,795 views.
Release Date:
2005-10-11
Secunia Advisory ID:
SA17163
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows XP Wireless Zero Configuration Wireless Profile Disclosure
Unpatched. Secunia Advisory 11 of 36 in 2005. 63,605 views.
Release Date:
2005-10-06
Secunia Advisory ID:
SA17064
Solution Status:
Unpatched
Criticality:
Impact:
Exposure of sensitive information
Where:
Local system
Short Description:
Laszlo Toth has discovered a security issue in Windows XP, which can be exploited by malicious, local users to gain access to certain sensitive information. [Read More]


Windows Registry Editor Utility String Concealment Weakness
Unpatched. Secunia Advisory 12 of 36 in 2005. 72,640 views.
Release Date:
2005-08-24
Secunia Advisory ID:
SA16560
Solution Status:
Unpatched
Criticality:
Impact:
Spoofing
Where:
Local system
Short Description:
Igor Franchuk has discovered a weakness in Microsoft Windows, which can be exploited to hide certain information. [Read More]


Microsoft Windows COM Object Instantiation Memory Corruption Vulnerability
Vendor Patch. Secunia Advisory 13 of 36 in 2005. 59,052 views.
Release Date:
2005-08-18
Secunia Advisory ID:
SA16480
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Internet Explorer, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Plug-and-Play Service Buffer Overflow
Vendor Patch. Secunia Advisory 14 of 36 in 2005. 25,936 views.
Release Date:
2005-08-09
Secunia Advisory ID:
SA16372
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
System access
Where:
From local network
Short Description:
ISS X-Force has reported a vulnerability in Microsoft Windows, which can be exploited by malicious users to gain escalated privileges or by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Telephony Service Vulnerability
Vendor Patch. Secunia Advisory 15 of 36 in 2005. 16,550 views.
Release Date:
2005-08-09
Secunia Advisory ID:
SA16354
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
System access
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges or by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Unspecified USB Device Driver Vulnerability
Unpatched. Secunia Advisory 16 of 36 in 2005. 34,316 views.
Release Date:
2005-07-27
Secunia Advisory ID:
SA16210
Solution Status:
Unpatched
Criticality:
Impact:
System access
Where:
Local system
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people with physical access to a vulnerable system to compromise it. [Read More]


Windows Remote Desktop Protocol Denial of Service Vulnerability
Vendor Patch. Secunia Advisory 17 of 36 in 2005. 37,622 views.
Release Date:
2005-07-14
Secunia Advisory ID:
SA16071
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Tom Ferris has reported a vulnerability in Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows Network Connections Service Denial of Service
Vendor Patch. Secunia Advisory 18 of 36 in 2005. 23,833 views.
Release Date:
2005-07-14
Secunia Advisory ID:
SA16065
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
Local system
Short Description:
bkbll has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]


Microsoft Windows Color Management Module Buffer Overflow
Vendor Patch. Secunia Advisory 19 of 36 in 2005. 28,663 views.
Release Date:
2005-07-12
Secunia Advisory ID:
SA16004
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Web Client Service Vulnerability
Vendor Patch. Secunia Advisory 20 of 36 in 2005. 15,303 views.
Release Date:
2005-06-14
Secunia Advisory ID:
SA15696
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
System access
Where:
From remote
Short Description:
Mark Litchfield has reported a vulnerability in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to compromise a user's system. [Read More]


Microsoft Windows Server Message Block Vulnerability
Vendor Patch. Secunia Advisory 21 of 36 in 2005. 18,538 views.
Release Date:
2005-06-14
Secunia Advisory ID:
SA15694
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Agent Trusted Internet Content Spoofing Vulnerability
Vendor Patch. Secunia Advisory 22 of 36 in 2005. 14,416 views.
Release Date:
2005-06-14
Secunia Advisory ID:
SA15689
Solution Status:
Vendor Patch
Criticality:
Impact:
Spoofing
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to spoof certain information and potentially trick a user into installing a malicious program. [Read More]


Microsoft Windows HTML Help Input Validation Vulnerability
Vendor Patch. Secunia Advisory 23 of 36 in 2005. 17,446 views.
Release Date:
2005-06-14
Secunia Advisory ID:
SA15683
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Internet Explorer Two Vulnerabilities
Vendor Patch. Secunia Advisory 24 of 36 in 2005. 22,976 views.
Release Date:
2005-06-14
Secunia Advisory ID:
SA15606
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Internet Explorer, which can be exploited by malicious people to disclose sensitive information and compromise a users system. [Read More]


Microsoft Telnet Client Information Disclosure Weakness
Vendor Patch. Secunia Advisory 25 of 36 in 2005. 15,149 views.
Release Date:
2005-06-14
Secunia Advisory ID:
SA15690
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
Where:
From remote
Short Description:
Gaël Delalleau has reported a weakness in Microsoft Windows, which can be exploited by malicious people to gain knowledge of various information. [Read More]


Microsoft Windows Step-by-Step Interactive Training Vulnerability
Vendor Patch. Secunia Advisory 26 of 36 in 2005. 15,872 views.
Release Date:
2005-06-14
Secunia Advisory ID:
SA15669
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
iDEFENSE Labs has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Windows Remote Desktop Protocol Private Key Disclosure
Unpatched. Secunia Advisory 27 of 36 in 2005. 29,330 views.
Release Date:
2005-06-06
Secunia Advisory ID:
SA15605
Solution Status:
Unpatched
Criticality:
Impact:
Hijacking
Where:
From remote
Short Description:
Massimiliano Montoro has reported a security issue in Microsoft Windows, which can be exploited by malicious people to conduct MitM (Man-in-the-Middle) attacks. [Read More]


Microsoft Windows Image Rendering Denial of Service Vulnerability
Unpatched. Secunia Advisory 28 of 36 in 2005. 22,483 views.
Release Date:
2005-04-22
Secunia Advisory ID:
SA15064
Solution Status:
Unpatched
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Andrew has discovered a vulnerability in Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows EMF File Denial of Service Vulnerability
Vendor Patch. Secunia Advisory 29 of 36 in 2005. 19,353 views.
Release Date:
2005-03-18
Secunia Advisory ID:
SA14631
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Hongzhen Zhou has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows TCP/IP Implementation Vulnerabilities
Vendor Patch. Secunia Advisory 30 of 36 in 2005. 29,926 views.
Release Date:
2005-03-07
Secunia Advisory ID:
SA14512
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system. [Read More]


Microsoft Windows SMB Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 31 of 36 in 2005. 17,522 views.
Release Date:
2005-02-08
Secunia Advisory ID:
SA11634
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
eEye Digital Security has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Drag and Drop Vulnerability
Vendor Patch. Secunia Advisory 32 of 36 in 2005. 18,995 views.
Release Date:
2005-02-08
Secunia Advisory ID:
SA14190
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Windows Anonymous Named Pipe Connection Information Disclosure
Vendor Patch. Secunia Advisory 33 of 36 in 2005. 17,780 views.
Release Date:
2005-02-08
Secunia Advisory ID:
SA14189
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
Where:
From local network
Short Description:
Jean-Baptiste Marchand has reported a weakness in Microsoft Windows 2000 and XP, which can be exploited by malicious people to gain knowledge of certain system information. [Read More]


Microsoft Various Products PNG Image Parsing Vulnerabilities
Vendor Patch. Secunia Advisory 34 of 36 in 2005. 16,487 views.
Release Date:
2005-02-08
Secunia Advisory ID:
SA14174
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in various Microsoft products, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Windows Registry Key Locking Denial of Service
Unpatched. Secunia Advisory 35 of 36 in 2005. 21,304 views.
Release Date:
2005-01-31
Secunia Advisory ID:
SA14061
Solution Status:
Unpatched
Criticality:
Impact:
DoS
Where:
Local system
Short Description:
Vladimir Kraljevic has reported a security issue in Windows, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]


Microsoft Windows Indexing Service Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 36 of 36 in 2005. 21,918 views.
Release Date:
2005-01-11
Secunia Advisory ID:
SA13802
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows XP and 2003, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Multiple Vulnerabilities
Partial Fix. Secunia Advisory 1 of 28 in 2004. 49,065 views.
Release Date:
2004-12-25
Secunia Advisory ID:
SA13645
Solution Status:
Partial Fix
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Flashsky has reported some vulnerabilities in Microsoft Windows, allowing malicious people to compromise a vulnerable system or cause a DoS (Denial of Service). [Read More]


Windows XP Firewall Dial-Up Security Issue
Vendor Patch. Secunia Advisory 2 of 28 in 2004. 19,310 views.
Release Date:
2004-12-17
Secunia Advisory ID:
SA13492
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
A security issue has been reported in Windows XP SP2, which erroneously causes the firewall to allow connections from the Internet. [Read More]


Microsoft Windows Kernel and LSASS Privilege Escalation Vulnerabilities
Vendor Patch. Secunia Advisory 3 of 28 in 2004. 17,450 views.
Release Date:
2004-12-14
Secunia Advisory ID:
SA13465
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Cesar Cerrudo has reported two vulnerabilities in Microsoft Windows, allowing malicious, local users to escalate their privileges. [Read More]


Microsoft Word for Windows Converter Buffer Overflow Vulnerabilities
Vendor Patch. Secunia Advisory 4 of 28 in 2004. 18,743 views.
Release Date:
2004-12-14
Secunia Advisory ID:
SA13462
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows HyperTerminal Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 5 of 28 in 2004. 17,917 views.
Release Date:
2004-12-14
Secunia Advisory ID:
SA13464
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Brett Moore has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Windows XP Internet Connection Firewall Bypass Weakness
Unpatched. Secunia Advisory 6 of 28 in 2004. 43,138 views.
Release Date:
2004-10-19
Secunia Advisory ID:
SA12793
Solution Status:
Unpatched
Criticality:
Impact:
Security Bypass
Where:
Local system
Short Description:
A weakness has been reported in Windows XP, which can be exploited to bypass certain rules in the Internet Connection Firewall (ICF). [Read More]


Microsoft Windows Shell and Program Group Converter Vulnerabilities
Vendor Patch. Secunia Advisory 7 of 28 in 2004. 17,265 views.
Release Date:
2004-10-13
Secunia Advisory ID:
SA12808
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows Compressed Folders Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 8 of 28 in 2004. 17,508 views.
Release Date:
2004-10-12
Secunia Advisory ID:
SA12805
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
eEye Digital Security has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 9 of 28 in 2004. 19,718 views.
Release Date:
2004-10-12
Secunia Advisory ID:
SA12804
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
DoS
System access
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in Microsoft Windows, which can be exploited to cause a DoS (Denial of Service), gain escalated privileges, or compromise a vulnerable system. [Read More]


Microsoft Windows NetDDE Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 10 of 28 in 2004. 16,950 views.
Release Date:
2004-10-12
Secunia Advisory ID:
SA12803
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
John Heasman has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows WebDAV XML Message Handler Denial of Service
Vendor Patch. Secunia Advisory 11 of 28 in 2004. 18,133 views.
Release Date:
2004-10-12
Secunia Advisory ID:
SA12801
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Amit Klein has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Windows Packet Fragmentation Handling Denial of Service Vulnerability
Unpatched. Secunia Advisory 12 of 28 in 2004. 16,757 views.
Release Date:
2004-10-01
Secunia Advisory ID:
SA12670
Solution Status:
Unpatched
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Gandalf The White has reported a variant of some known vulnerabilities in Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Multiple Products JPEG Processing Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 13 of 28 in 2004. 56,111 views.
Release Date:
2004-09-14
Secunia Advisory ID:
SA12528
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Nick DeBaggis has reported a vulnerability in multiple Microsoft products, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows showHelp and HTML Help Vulnerabilities
Vendor Patch. Secunia Advisory 14 of 28 in 2004. 16,333 views.
Release Date:
2004-07-13
Secunia Advisory ID:
SA12059
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
System access
Where:
From remote
Short Description:
Microsoft has issued an update for Windows. This fixes two vulnerabilities, allowing malicious websites to compromise a vulnerable system. [Read More]


Microsoft Windows / Internet Explorer File Download Extension Spoofing
Vendor Patch. Secunia Advisory 15 of 28 in 2004. 18,277 views.
Release Date:
2004-07-13
Secunia Advisory ID:
SA12058
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
Microsoft has issued an update for Microsoft Windows. This fixes a vulnerability, allowing malicious web sites to spoof the extension of files being downloaded. [Read More]


Microsoft Windows Task Scheduler Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 16 of 28 in 2004. 17,637 views.
Release Date:
2004-07-13
Secunia Advisory ID:
SA12060
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Microsoft has issued an update for Windows. This fixes a vulnerability, allowing malicious websites to execute arbitrary code on a vulnerable system. [Read More]


Microsoft Java Virtual Machine Cross-Site Communication Vulnerability
Unpatched. Secunia Advisory 17 of 28 in 2004. 19,991 views.
Release Date:
2004-07-12
Secunia Advisory ID:
SA12047
Solution Status:
Unpatched
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
Marc Schoenefeld has reported a vulnerability in Microsoft Java Virtual Machine, allowing Java applets originating from different domains to communicate. [Read More]


Microsoft DirectPlay Packet Validation Denial of Service Vulnerability
Vendor Patch. Secunia Advisory 18 of 28 in 2004. 15,739 views.
Release Date:
2004-06-08
Secunia Advisory ID:
SA11802
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
John Lampe has discovered a vulnerability in Microsoft DirectPlay, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows "desktop.ini" Arbitrary File Execution Vulnerability
Vendor Patch. Secunia Advisory 19 of 28 in 2004. 40,023 views.
Release Date:
2004-05-18
Secunia Advisory ID:
SA11633
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Roozbeh Afrasiabi has reported a vulnerability in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. [Read More]


Microsoft Windows Help and Support Center URL Validation Vulnerability
Vendor Patch. Secunia Advisory 20 of 28 in 2004. 21,002 views.
Release Date:
2004-05-11
Secunia Advisory ID:
SA11590
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Microsoft has issued patches for Microsoft Windows to fix a vulnerability in the Help and Support Center. [Read More]


Windows Explorer / Internet Explorer Long Share Name Buffer Overflow
Vendor Patch. Secunia Advisory 21 of 28 in 2004. 73,330 views.
Release Date:
2004-04-26
Secunia Advisory ID:
SA11482
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
Rodrigo Gutierrez has discovered a vulnerability in Windows and Internet Explorer, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows RPC/DCOM Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 22 of 28 in 2004. 18,067 views.
Release Date:
2004-04-13
Secunia Advisory ID:
SA11065
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
Microsoft has issued an advisory regarding multiple vulnerabilities in RPC/DCOM, where the most serious can potentially lead to a system compromise. [Read More]


Microsoft Windows 14 Vulnerabilities
Vendor Patch. Secunia Advisory 23 of 28 in 2004. 36,093 views.
Release Date:
2004-04-13
Secunia Advisory ID:
SA11064
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
DoS
System access
Where:
From remote
Short Description:
Microsoft has acknowledged 14 vulnerabilities in the Windows operating system, where the most serious can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Jet Database Engine Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 24 of 28 in 2004. 15,826 views.
Release Date:
2004-04-13
Secunia Advisory ID:
SA11068
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Matt Thompson has discovered a vulnerability in Microsoft Jet Database Engine, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Enhanced/Windows Metafile Handling Vulnerability
Unpatched. Secunia Advisory 25 of 28 in 2004. 24,193 views.
Release Date:
2004-02-25
Secunia Advisory ID:
SA10968
Solution Status:
Unpatched
Criticality:
Impact:
Privilege escalation
DoS
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Windows XP, which potentially can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Windows ASN.1 Library Integer Overflow Vulnerabilities
Vendor Patch. Secunia Advisory 26 of 28 in 2004. 28,760 views.
Release Date:
2004-02-10
Secunia Advisory ID:
SA10759
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
eEye Digital Security has discovered some vulnerabilities in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Windows XP Malicious Folder Automatic Code Execution Vulnerability
Unpatched. Secunia Advisory 27 of 28 in 2004. 48,215 views.
Release Date:
2004-01-26
Secunia Advisory ID:
SA10708
Solution Status:
Unpatched
Criticality:
Impact:
Privilege escalation
System access
Where:
From remote
Short Description:
http-equiv has reported a vulnerability in Windows XP, which can be exploited by malicious people to compromise a user's system or gain escalated privileges. [Read More]


Microsoft Data Access Components Broadcast Reply Buffer Overflow
Vendor Patch. Secunia Advisory 28 of 28 in 2004. 16,916 views.
Release Date:
2004-01-13
Secunia Advisory ID:
SA10616
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
Microsoft has reported a vulnerability in MDAC (Microsoft Data Access Components), which potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft Windows Workstation Service Buffer Overflow
Vendor Patch. Secunia Advisory 1 of 29 in 2003. 17,693 views.
Release Date:
2003-11-11
Secunia Advisory ID:
SA10193
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
Microsoft has issued patches for Windows 2000 and XP. These fix a vulnerability in the Workstation service, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Microsoft HTML Help Control Privilege Escalation Vulnerability
Unpatched. Secunia Advisory 2 of 29 in 2003. 19,615 views.
Release Date:
2003-10-27
Secunia Advisory ID:
SA10066
Solution Status:
Unpatched
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Microsoft HTML Help, which can be exploited by malicious, local users to escalate their privileges. [Read More]


Microsoft Windows Buffer Overflow in ListBox and ComboBox Control
Vendor Patch. Secunia Advisory 3 of 29 in 2003. 14,996 views.
Release Date:
2003-10-15
Secunia Advisory ID:
SA10014
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Microsoft has issued patches to fix a vulnerability in Microsoft Windows allowing malicious users to escalate their privileges. [Read More]


Microsoft Windows Help and Support Center Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 4 of 29 in 2003. 16,904 views.
Release Date:
2003-10-15
Secunia Advisory ID:
SA10013
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Microsoft has issued patches for Microsoft Windows to fix a vulnerability in the Help and Support Center. [Read More]


Microsoft Windows Buffer Overflow in Messenger Service
Vendor Patch. Secunia Advisory 5 of 29 in 2003. 22,976 views.
Release Date:
2003-10-15
Secunia Advisory ID:
SA10012
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
Microsoft has issued patches for Microsoft Windows to fix a buffer overflow vulnerability in Messenger Service, which could lead to execution of arbitrary code. [Read More]


Microsoft Windows May Allow Installation of Arbitrary ActiveX Controls
Vendor Patch. Secunia Advisory 6 of 29 in 2003. 17,160 views.
Release Date:
2003-10-15
Secunia Advisory ID:
SA10010
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Microsoft has issued patches to fix a vulnerability in Microsoft Windows (Internet Explorer) allowing malicious HTML documents like web pages or emails to install arbitrary ActiveX controls. [Read More]


Windows RPC Race Condition Denial of Service Vulnerability
Vendor Patch. Secunia Advisory 7 of 29 in 2003. 19,645 views.
Release Date:
2003-10-15
Secunia Advisory ID:
SA9978
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
ISS X-Force has reported a vulnerability in some versions of Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows Unauthorised Thread Termination
Unpatched. Secunia Advisory 8 of 29 in 2003. 18,495 views.
Release Date:
2003-10-03
Secunia Advisory ID:
SA9921
Solution Status:
Unpatched
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been reported in Windows, which can be exploited by malicious, local users to terminate certain privileged programs. [Read More]


Microsoft Windows TCP Packet Information Disclosure
Unpatched. Secunia Advisory 9 of 29 in 2003. 17,177 views.
Release Date:
2003-09-22
Secunia Advisory ID:
SA9799
Solution Status:
Unpatched
Criticality:
Impact:
Exposure of sensitive information
Where:
From remote
Short Description:
A vulnerability has been identified in the handling of TCP packets in Microsoft Windows 2000 and Windows XP, which potentially can expose sensitive information. [Read More]


Microsoft Windows RPCSS Service DCOM Interface Vulnerabilities
Vendor Patch. Secunia Advisory 10 of 29 in 2003. 34,024 views.
Release Date:
2003-09-10
Secunia Advisory ID:
SA9692
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
Three vulnerabilities have been identified in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system or cause a DoS (Denial of Service). [Read More]


Microsoft Windows NetBIOS Random Memory Content Disclosure
Vendor Patch. Secunia Advisory 11 of 29 in 2003. 13,818 views.
Release Date:
2003-09-03
Secunia Advisory ID:
SA9665
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Where:
From local network
Short Description:
A vulnerability has been discovered in all supported Windows versions except Windows ME, which can be exploited by malicious people to disclose potentially sensitive information. [Read More]


Microsoft MDAC Buffer Overflow
Vendor Patch. Secunia Advisory 12 of 29 in 2003. 14,353 views.
Release Date:
2003-08-20
Secunia Advisory ID:
SA9579
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
Microsoft has issued a patch for MDAC due to a vulnerability which allows malicious people to cause a buffer overflow. [Read More]


Microsoft Windows DirectX Remotely Exploitable Buffer Overflow
Vendor Patch. Secunia Advisory 13 of 29 in 2003. 23,960 views.
Release Date:
2003-07-23
Secunia Advisory ID:
SA9335
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been identified in DirectX allowing malicious people to gain system access. [Read More]


Windows RPC DCOM Interface Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 14 of 29 in 2003. 21,849 views.
Release Date:
2003-07-16
Secunia Advisory ID:
SA9287
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
A vulnerability has been identified in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Windows SMB Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 15 of 29 in 2003. 13,728 views.
Release Date:
2003-07-09
Secunia Advisory ID:
SA9225
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
DoS
System access
Where:
From local network
Short Description:
A vulnerability has been identified in some versions of Windows, which can be exploited by malicious users to cause a DoS (Denial of Service) on a vulnerable system and potentially compromise it. [Read More]


Windows NetMeeting Directory Traversal Vulnerability
Vendor Patch. Secunia Advisory 16 of 29 in 2003. 15,882 views.
Release Date:
2003-07-02
Secunia Advisory ID:
SA9170
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been identified in Windows NetMeeting, which can be exploited by malicious people to overwrite arbitrary files on a user's system with the privileges of the user. [Read More]


Microsoft Windows HTML Converter Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 17 of 29 in 2003. 16,119 views.
Release Date:
2003-06-25
Secunia Advisory ID:
SA9113
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
A vulnerability has been identified in all supported Windows versions, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Windows XP "shell32.dll" Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 18 of 29 in 2003. 43,161 views.
Release Date:
2003-05-19
Secunia Advisory ID:
SA8788
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been identified in Windows XP, which potentially can be exploited by malicious users to escalate their privileges on a vulnerable system. [Read More]


Microsoft Windows Media Player skin download vulnerability
Vendor Patch. Secunia Advisory 19 of 29 in 2003. 50,167 views.
Release Date:
2003-05-07
Secunia Advisory ID:
SA8742
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A flaw has been identified in Microsoft Windows Media Player, which could allow malicious HTML documents to place arbitrary files on the users system. [Read More]


Microsoft Shell Light-Weight Utility Library Denial of Service
Vendor Patch. Secunia Advisory 20 of 29 in 2003. 36,059 views.
Release Date:
2003-04-23
Secunia Advisory ID:
SA8642
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
A vulnerability identified in a library included in Windows XP and Internet Explorer version 4.0 and newer can be exploited to cause a DoS (Denial of Service) on certain applications. [Read More]


Windows NTFS File System Information Disclosure
Unpatched. Secunia Advisory 21 of 29 in 2003. 18,276 views.
Release Date:
2003-04-22
Secunia Advisory ID:
SA8635
Solution Status:
Unpatched
Criticality:
Impact:
Exposure of system information
Exposure of sensitive information
Where:
Local system
Short Description:
Matthew Murphy has reported a security issue in Windows, which potentially can be exploited by malicious, local users to gain knowledge of sensitive information. [Read More]


Windows Kernel Privilege Escalation Vulnerability
Vendor Patch. Secunia Advisory 22 of 29 in 2003. 10,838 views.
Release Date:
2003-04-16
Secunia Advisory ID:
SA8609
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been identified in some versions of Windows, which can be exploited by malicious users on a vulnerable system to escalate their privileges. [Read More]


Microsoft Virtual Machine Bytecode Verifier Vulnerability
Vendor Patch. Secunia Advisory 23 of 29 in 2003. 15,975 views.
Release Date:
2003-04-09
Secunia Advisory ID:
SA8559
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability identified in Microsoft VM (Virtual Machine) shipped with almost all versions of Windows (except some versions of Windows XP) can be exploited by malicious people to compromise a user's system. [Read More]


Windows Script Engine Heap Overflow
Vendor Patch. Secunia Advisory 24 of 29 in 2003. 11,161 views.
Release Date:
2003-03-19
Secunia Advisory ID:
SA8346
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability identified in all currently supported versions of Microsoft Windows can be exploited by malicious people to compromise a user's system. [Read More]


Windows 2000/XP PostMessage Password Disclosure
Unpatched. Secunia Advisory 25 of 29 in 2003. 15,013 views.
Release Date:
2003-03-18
Secunia Advisory ID:
SA8329
Solution Status:
Unpatched
Criticality:
Impact:
Exposure of sensitive information
Where:
Local system
Short Description:
An information disclosure vulnerability has been identified in Windows 2000 and Windows XP, which can be exploited by a malicious, local user to gain knowledge of sensitive information. [Read More]


Windows ME Help and Support Center Buffer Overflow
Vendor Patch. Secunia Advisory 26 of 29 in 2003. 9,347 views.
Release Date:
2003-02-26
Secunia Advisory ID:
SA8161
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability in the Windows ME version of Help and Support Center can be exploited by malicious people to compromise a user's system. [Read More]


Windows XP Redirector Privilege Escalation
Vendor Patch. Secunia Advisory 27 of 29 in 2003. 12,103 views.
Release Date:
2003-02-05
Secunia Advisory ID:
SA8005
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Microsoft has published a security bulletin describing a boundary error in Windows XP, which can be exploited by malicious local users on a system to escalate their privileges. [Read More]


Microsoft Windows buffer overflow in Locator Service
Vendor Patch. Secunia Advisory 28 of 29 in 2003. 10,753 views.
Release Date:
2003-01-23
Secunia Advisory ID:
SA7926
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Microsoft has issued a security bulletin regarding a buffer overflow in the Locator Service. The Locater service only runs by default on Windows NT and 2000 domain controllers. [Read More]


Microsoft Windows crashes on invalid font file
Unpatched. Secunia Advisory 29 of 29 in 2003. 13,056 views.
Release Date:
2003-01-07
Secunia Advisory ID:
SA7824
Solution Status:
Unpatched
Criticality:
Impact:
DoS
Where:
Local system
Short Description:
Microsoft Windows 2000 and XP does not handle fonts correctly. Malformed font files can bring the system to an immediate reboot if viewed in the font viewer (fontview). [Read More]


Microsoft Windows Certificate Chain vulnerability
Unpatched. Secunia Advisory 1 of 15 in 2002. 18,549 views.
Release Date:
2002-12-30
Secunia Advisory ID:
SA7793
Solution Status:
Unpatched
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Microsoft Windows is flawed in the way it trusts certificates. Microsoft Windows File Protection will automatically trust software that has been digitally signed with certificates rooted in any of the Trusted Root Certification Authorities. [Read More]


Windows XP Desktop buffer overflow
Vendor Patch. Secunia Advisory 2 of 15 in 2002. 14,270 views.
Release Date:
2002-12-19
Secunia Advisory ID:
SA7747
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Windows XP is flawed in the way it extracts attribute information from audio files like .mp3 and .wma - this vulnerability is within Windows XP and not the Media Player. [Read More]


Microsoft Windows SMB signing bypass
Vendor Patch. Secunia Advisory 3 of 15 in 2002. 11,627 views.
Release Date:
2002-12-12
Secunia Advisory ID:
SA7689
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Privilege escalation
Where:
From local network
Short Description:
Microsoft Windows 2000 and XP supports digital signing of SMB traffic. However it is possible for malicious persons to downgrade / turn off signing even if the network adminstrator has required this. [Read More]


Microsoft Windows Window Messaging Privilege Escalation Vulnerability
Partial Fix. Secunia Advisory 4 of 15 in 2002. 12,235 views.
Release Date:
2002-12-12
Secunia Advisory ID:
SA7688
Solution Status:
Partial Fix
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been identified in Microsoft Windows, which can be exploited by malicious, local users to escalate their privileges on a vulnerable system. [Read More]


Microsoft Windows Virtual Machine multiple vulnerabilities
Vendor Patch. Secunia Advisory 5 of 15 in 2002. 11,906 views.
Release Date:
2002-12-12
Secunia Advisory ID:
SA7687
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Microsoft has issued a new build of their virtual machine, it fixes a number of issues, some which previously has been published by Secunia. [Read More]


Windows XP expose registered wireless access points
Unpatched. Secunia Advisory 6 of 15 in 2002. 13,729 views.
Release Date:
2002-12-09
Secunia Advisory ID:
SA7669
Solution Status:
Unpatched
Criticality:
Impact:
Exposure of system information
Where:
From remote
Short Description:
Windows XP is flawed in the way it searches for wireless access points if a registered access point isn't are available. [Read More]


Windows XP admin downgrade problem
Unpatched. Secunia Advisory 7 of 15 in 2002. 14,305 views.
Release Date:
2002-12-02
Secunia Advisory ID:
SA7629
Solution Status:
Unpatched
Criticality:
Impact:
Security Bypass
Where:
Local system
Short Description:
Windows XP when used in a workgroup environment, fails to remove all privileges from users who previously enjoyed administrative privileges. [Read More]


Microsoft PPTP Implementation Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 8 of 15 in 2002. 10,050 views.
Release Date:
2002-10-31
Secunia Advisory ID:
SA7420
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Windows RPC Endpoint Mapper Denial of Service
Vendor Patch. Secunia Advisory 9 of 15 in 2002. 11,749 views.
Release Date:
2002-10-19
Secunia Advisory ID:
SA7347
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
A vulnerability has been identified in Windows, which can be exploited by a malicious person to cause a DoS (Denial of Service) on some services on a vulnerable system. [Read More]


Windows XP arbitrary file deletion
Vendor Patch. Secunia Advisory 10 of 15 in 2002. 9,509 views.
Release Date:
2002-10-17
Secunia Advisory ID:
SA7324
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
Where:
From remote
Short Description:
Windows XP Help and Support Center allows hackers to create a malicious web page which could delete arbitrary files and folders. [Read More]


Microsoft Windows HTML Help facility buffer overflow
Vendor Patch. Secunia Advisory 11 of 15 in 2002. 6,807 views.
Release Date:
2002-10-03
Secunia Advisory ID:
SA7199
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
The HTML Help facility contains a number of vulnerabilities, which possibly could allow attackers to gain system access. [Read More]


Microsoft Windows vulnerabilities in zip utility
Vendor Patch. Secunia Advisory 12 of 15 in 2002. 7,111 views.
Release Date:
2002-10-03
Secunia Advisory ID:
SA7198
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Two vulnerabilities exists in the zip funtion included in Windows XP/ME/98, these could allow attackers to gain system access. [Read More]


Microsoft PPTP Client and Server Pre-Authentication Buffer Overflow
Vendor Patch. Secunia Advisory 13 of 15 in 2002. 7,538 views.
Release Date:
2002-09-26
Secunia Advisory ID:
SA7164
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system. [Read More]


Microsoft issues patches to Virtual Machine vulnerabilities
Vendor Patch. Secunia Advisory 14 of 15 in 2002. 7,129 views.
Release Date:
2002-09-19
Secunia Advisory ID:
SA7129
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Microsoft has issued patches to three vulnerabilities in VM JDBC. [Read More]


Microsoft: Certificate Validation Flaw Enables Identity Spoofing
Vendor Patch. Secunia Advisory 15 of 15 in 2002. 12,872 views.
Release Date:
2002-09-05
Secunia Advisory ID:
SA7072
Solution Status:
Vendor Patch
Criticality:
Impact:
Spoofing
Where:
From remote
Short Description:
Microsoft admits that a critical flaw exists in its Crypto API which evaluates certificates. [Read More]