
CVE-2010-0248 – Microsoft Internet Explorer item Object Memory Corruption Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2010-0248
21 Jan 2010 — Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability." Microsoft Internet Explorer 6, 6 SP1, 7 y 8 no maneja de manera apropiada los objetos en memoria lo que permite a atacantes remotos ejecutar código de su elección accediendo a un objeto que (1) no fue cor... • https://www.exploit-db.com/exploits/18642 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-416: Use After Free •

CVE-2010-0249 – Microsoft Internet Explorer - 'Aurora' Memory Corruption (MS10-002)
https://notcve.org/view.php?id=CVE-2010-0249
15 Jan 2010 — Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora,... • https://www.exploit-db.com/exploits/16599 • CWE-416: Use After Free •

CVE-2010-0018
https://notcve.org/view.php?id=CVE-2010-0018
13 Jan 2010 — Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code via compressed data that represents a crafted EOT font, aka "Microtype Express Compressed Fonts Integer Flaw in the LZCOMP Decompressor Vulnerability." Desbordamiento de enteros en el motor de fuente de Embedded OpenType ... • http://blogs.technet.com/srd/archive/2010/01/12/ms10-001-font-file-decompression-vulnerability.aspx • CWE-189: Numeric Errors •

CVE-2009-4210
https://notcve.org/view.php?id=CVE-2009-4210
13 Dec 2009 — The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted media content. El codec Indeo en Microsoft Windows 2000 SP4, XP SP2 y SP3, y Server 2003 SP2 permite a atacantes remotos una denegación de servicio (corrupción de memoria) o posiblemente tener un impacto sin especificar otro impacto a través de contenido multimedia manipulado. • http://secunia.com/advisories/37592 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2009-4311
https://notcve.org/view.php?id=CVE-2009-4311
13 Dec 2009 — Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Paul Byrne of NGS Software. NOTE: this might overlap CVE-2008-3615. Vulnerabilidad sin especificar en el codec Indeo en Microsoft Windows 2000 SP4, XP SP2 y SP3, y Server 2003 SP2 permite a atacantes remotos ejecutar código arbitrario a través de contenido multimedia manipulado, como reporto Pa... • http://secunia.com/advisories/37592 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2009-4312
https://notcve.org/view.php?id=CVE-2009-4312
13 Dec 2009 — Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Dave Lenoe of Adobe. Vulnerabilidad sin especificar en el codec Indeo en Microsoft Windows 2000 SP4, XP SP2 y SP3, y Server 2003 SP2 permite a atacantes remotos ejecutar codigo arbitrario a través de contenido multimedia, como reporto Dave Lenoe de Adobe. • http://secunia.com/advisories/37592 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2009-4313
https://notcve.org/view.php?id=CVE-2009-4313
13 Dec 2009 — ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed data in a stream in a media file, as demonstrated by an AVI file. ir32_32.dll 3.24.15.3 en el codec Indeo32 en Microsoft Windows 2000 SP4, XP SP2 y SP3, y Server 2003 SP2 permite a atacantes remotos producir una denegación de servicio (corrupción de memoria libre) o ejecutar código arbitrar... • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=835 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2009-3675
https://notcve.org/view.php?id=CVE-2009-3675
09 Dec 2009 — LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, aka "Local Security Authority Subsystem Service Resource Exhaustion Vulnerability." LSASS.exe en Local Security Authority Subsystem Service (LSASS) en Microsoft Windows 2000 SP4, XP SP2 y SP3 y Server 2003 SP2 permite a atacantes remotos autenticados pr... • http://www.us-cert.gov/cas/techalerts/TA09-342A.html • CWE-399: Resource Management Errors •

CVE-2009-3677
https://notcve.org/view.php?id=CVE-2009-3677
09 Dec 2009 — The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability." Internet Authentication Service (IAS) en Microsoft Windows 2000 SP4, XP SP2 y SP3, Server 2003 SP... • http://www.securitytracker.com/id?1023291 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-255: Credentials Management Errors •

CVE-2009-2506
https://notcve.org/view.php?id=CVE-2009-2506
09 Dec 2009 — Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with an invalid number of property names in the DocumentSummaryInformation stream, which triggers a heap-based buffer overflow. Desbordamiento de enteros en los convertidores de texto en Microsoft Office Word 2002 SP3 y 2003 SP3; Works versión 8.5; Office ... • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=834 • CWE-189: Numeric Errors •