|
4841
|
-
10.0
|
HIGH
|
The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication r…
|
CWE-287
Improper Authentication
|
CVE-2009-2505
|
cpe:2.3:o:microsoft:windows_server_2008:sp2:x64 cpe:2.3:o:microsoft:windows_server_2008:sp2:x32
|
|
|
|
|
2026-04-23 09:35
2009-12-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4842
|
-
7.1
|
HIGH
|
The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) v…
|
CWE-399
Resource Management Errors
|
CVE-2009-3676
|
cpe:2.3:o:microsoft:windows_server_2008:r2:*
|
|
|
|
|
2026-04-23 09:35
2009-11-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4843
|
-
9.3
|
HIGH
|
win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote atta…
|
CWE-94
Code Injection
|
CVE-2009-2514
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:gold
|
|
|
|
|
2026-04-23 09:35
2009-11-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4844
|
-
7.2
|
HIGH
|
The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properl…
|
CWE-20
Improper Input Validation
|
CVE-2009-2513
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:gold
|
|
|
|
|
2026-04-23 09:35
2009-11-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4845
|
-
7.8
|
HIGH
|
Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2; Active Directory Application Mode (ADAM) on Windo…
|
CWE-399
Resource Management Errors
|
CVE-2009-1928
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:gold
|
|
|
|
|
2026-04-23 09:35
2009-11-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4846
|
-
7.2
|
HIGH
|
win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecifi…
|
CWE-20
Improper Input Validation
|
CVE-2009-1127
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:gold
|
|
|
|
|
2026-04-23 09:35
2009-11-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4847
|
-
10.0
|
HIGH
|
Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allow…
|
CWE-94
Code Injection
|
CVE-2009-2532
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:w…
|
|
|
|
|
2026-04-23 09:35
2009-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4848
|
-
9.3
|
HIGH
|
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly ini…
|
CWE-94
Code Injection
|
CVE-2009-2531
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:w…
|
|
|
|
|
2026-04-23 09:35
2009-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4849
|
-
9.3
|
HIGH
|
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly ini…
|
CWE-94
Code Injection
|
CVE-2009-2530
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:w…
|
|
|
|
|
2026-04-23 09:35
2009-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4850
|
8.1
9.3
|
HIGH
Network
|
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted …
|
CWE-94
Code Injection
|
CVE-2009-2529
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:w…
|
|
|
|
|
2026-04-23 09:35
2009-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|