
CVE-2003-0533 – Microsoft LSASS Service - DsRolerUpgradeDownlevelServer Overflow (MS04-011)
https://notcve.org/view.php?id=CVE-2003-0533
16 Apr 2004 — Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm. Desbordamiento de búfer basado en la pi... • https://www.exploit-db.com/exploits/16368 •

CVE-2003-0806
https://notcve.org/view.php?id=CVE-2003-0806
16 Apr 2004 — Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code. Desbordamiento de búfer en el proceso de inicio de sesión de Windows (winlogon) en Microsoft Windows NT 4.0 SP6a, 2000 SP2 a SP4, y XP SP1, cuando lo hace un miembro de un dominio, permite a atacantes remotos ejecutar código de su elección. • http://www.ciac.org/ciac/bulletins/o-114.shtml •

CVE-2003-0807
https://notcve.org/view.php?id=CVE-2003-0807
16 Apr 2004 — Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request. Desbordamiento de búfer en los componentes (1) Servicios de Internet COM y (2) Proxy RPC sobre HTTP de Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, y Server 2003 permite a atacantes remotos causar una denegación de servicio ... • http://securitytracker.com/alerts/2004/Apr/1009762.html •

CVE-2003-0906
https://notcve.org/view.php?id=CVE-2003-0906
16 Apr 2004 — Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image. Desbordamiento de búfer en el dibujado de los formatos de imagen (1) Windows Metafile (WMF) o (2) Enhanced Metafile (EMF) en Microsoft Windows NT 4.0 SP6a, 2000 SP2 a SP4, y XP SP1 permite a atacantes remotos ejecutar código arbitrario mediante una ima... • http://www.kb.cert.org/vuls/id/547028 •

CVE-2003-0910 – Microsoft Windows NT 4.0/2000 - Local Descriptor Table Privilege Escalation (MS04-011)
https://notcve.org/view.php?id=CVE-2003-0910
16 Apr 2004 — The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory. La función NtSetLdtEntries en el interfaz de programación de la Tabla de Descriptores L ocales (LDT) de Windows NT 4.0 y Windows 2000 permitea atacantes locales ganar acceso a memoria del kernel y ejecutar código ... • https://www.exploit-db.com/exploits/23989 •

CVE-2004-0118
https://notcve.org/view.php?id=CVE-2004-0118
16 Apr 2004 — The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code. El componente del subsistema de la Máquina Virtual DOS (VDM) en Windows NT 4.0 y Windows 2000 no valida adecuadamente estructuras de sistema, lo que permite a usuarios locales acceder a memoria protegida del kernel y ejecutar código de su elección. • http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020070.html •

CVE-2004-0123
https://notcve.org/view.php?id=CVE-2004-0123
16 Apr 2004 — Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code. Vulnerabilidad de doble liberación de memoria en la librería ASN.1 usada en Windows NT 4.0, Windows 2000, Windows XP, y Windows Server 2003, permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código de su elección. • http://www.ciac.org/ciac/bulletins/o-114.shtml • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2004-0124
https://notcve.org/view.php?id=CVE-2004-0124
16 Apr 2004 — The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability." El interfaz RPC DCOM de Microsoft Windows NT 4.0, 2000, XP y Server 2003 permite a atacantes remotos causar comunicaciones de red mediante una llamada de "alterar contexto" conteniendo datos adicionales, también conocida como "Vulnerabilidad de Identidad de Objeto". • http://secunia.com/advisories/11065 •

CVE-2003-0719 – Microsoft IIS 5.0 - SSL Remote Buffer Overflow (MS04-011)
https://notcve.org/view.php?id=CVE-2003-0719
16 Apr 2004 — Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets. Desbordamiento de búfer en la implementación del protocolo Private Communications Transport (PCT) en la librería SSL de Microsoft, usada en Microsoft Windows NT 4.0 SP6a, 2000 SP2 a SP4, XP ... • https://www.exploit-db.com/exploits/275 •

CVE-2003-0825
https://notcve.org/view.php?id=CVE-2003-0825
03 Mar 2004 — The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code. El Servicio de Nombres de Internet de Windows (WINS) en Microsoft Windows Server 2003, y posiblemente Windows NT y Server 2000 no valida adecuadamente la longitud de ciertos paquetes, lo que permite a ciertos paquetes causar una denegación de ser... • http://www.ciac.org/ciac/bulletins/o-077.shtml • CWE-20: Improper Input Validation •