VYPR

Windows Server 2003

by Microsoft

Source repositories

CVEs (5,318)

  • CVE-2005-1207Jun 14, 2005
    risk 0.01cvss epss 0.07

    Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.

  • CVE-2004-0892Jan 27, 2005
    risk 0.01cvss epss 0.17

    Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup…

  • CVE-2003-0825Mar 3, 2004
    risk 0.01cvss epss 0.12

    The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.

  • CVE-2003-0904Jan 20, 2004
    risk 0.01cvss epss 0.08

    Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g.…

  • CVE-2003-0813Nov 17, 2003
    risk 0.01cvss epss 0.15

    A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it…

  • CVE-2003-0839Nov 17, 2003
    risk 0.01cvss epss 0.14

    Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link.

  • CVE-2002-2189Dec 31, 2002
    risk 0.01cvss epss 0.07

    Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote attackers to execute arbitrary web script via a link.

  • CVE-2026-58638MedJul 14, 2026
    risk 0.00cvss 6.0epss 0.00

    Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-58637HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58632HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58629HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58628HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58627HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

  • CVE-2026-58626HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

  • CVE-2026-58619HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58613HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58594HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58547MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58546MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-58545MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

Page 240 of 266