|
4851
|
-
7.8
|
HIGH
|
Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and…
|
CWE-399
Resource Management Errors
|
CVE-2009-2526
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:w…
|
|
|
|
|
2026-04-23 09:35
2009-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4852
|
-
7.8
|
HIGH
|
Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, a…
|
CWE-189
Numeric Errors
|
CVE-2009-2524
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:w…
|
|
|
|
|
2026-04-23 09:35
2009-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4853
|
-
7.2
|
HIGH
|
Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a craf…
|
CWE-189
Numeric Errors
|
CVE-2009-2515
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:w…
|
|
|
|
|
2026-04-23 09:35
2009-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4854
|
-
6.8
|
MEDIUM
|
The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used…
|
CWE-310
Cryptographic Issues
|
CVE-2009-2510
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:w…
|
|
|
|
|
2026-04-23 09:35
2009-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4855
|
-
9.3
|
HIGH
|
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute…
|
CWE-94
Code Injection
|
CVE-2009-2497
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:sp2
|
|
|
|
|
2026-04-23 09:35
2009-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4856
|
8.8
9.3
|
HIGH
Network
|
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, …
|
CWE-94
Code Injection
|
CVE-2009-1547
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:w…
|
|
|
|
|
2026-04-23 09:35
2009-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4857
|
-
9.3
|
HIGH
|
Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a …
|
CWE-94
Code Injection
|
CVE-2009-0091
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:sp2
|
|
|
|
|
2026-04-23 09:35
2009-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4858
|
-
9.3
|
HIGH
|
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrar…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0090
|
cpe:2.3:o:microsoft:windows_server_2008:-:sp2 cpe:2.3:o:microsoft:windows_server_2008:-:sp2
|
|
|
|
|
2026-04-23 09:35
2009-10-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4859
|
-
10.0
|
HIGH
|
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute…
|
CWE-399
Resource Management Errors
|
CVE-2009-3103
|
cpe:2.3:o:microsoft:windows_server_2008:sp2:x64 cpe:2.3:o:microsoft:windows_server_2008:sp2:x32
|
|
|
|
|
2026-04-23 09:35
2009-09-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4860
|
-
9.3
|
HIGH
|
The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary…
|
CWE-94
Code Injection
|
CVE-2009-2519
|
cpe:2.3:o:microsoft:windows_2000:-:sp4
|
|
|
|
|
2026-04-23 09:35
2009-09-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|