CVE-2004-0116
https://notcve.org/view.php?id=CVE-2004-0116
An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field. Una función de activación en el servicio RPCSS relacionada con la activación DCOM de Microsoft Windows 2000, XP y 2004 permite a atacantes remotos causar una denegación de servicio (consumición de memoria) mediante una petición de activación con un campo de longitud largo. • http://secunia.com/advisories/11065 http://securitytracker.com/alerts/2004/Apr/1009758.html http://www.ciac.org/ciac/bulletins/o-115.shtml http://www.eeye.com/html/Research/Advisories/AD20040413A.html http://www.kb.cert.org/vuls/id/417052 http://www.securityfocus.com/bid/10127 http://www.us-cert.gov/cas/techalerts/TA04-104A.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-012 https://exchange.xforce.ibmcloud.com/vulnerabilities/15708 https: •
CVE-2004-0123
https://notcve.org/view.php?id=CVE-2004-0123
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code. Vulnerabilidad de doble liberación de memoria en la librería ASN.1 usada en Windows NT 4.0, Windows 2000, Windows XP, y Windows Server 2003, permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código de su elección. • http://www.ciac.org/ciac/bulletins/o-114.shtml http://www.kb.cert.org/vuls/id/255924 http://www.securityfocus.com/bid/10118 http://www.us-cert.gov/cas/techalerts/TA04-104A.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011 https://exchange.xforce.ibmcloud.com/vulnerabilities/15713 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1007 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2003-0663
https://notcve.org/view.php?id=CVE-2003-0663
Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message. Vulnerabilidad desconocida en Local Security Authority Subsystem Service (LSASS) en controladores de dominio Windows 2000 permite a atacantes remotos causar una denegación de servicio mediante un mensaje LDAP elaborado. • http://www.ciac.org/ciac/bulletins/o-114.shtml http://www.kb.cert.org/vuls/id/639428 http://www.securityfocus.com/bid/10114 http://www.us-cert.gov/cas/techalerts/TA04-104A.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011 https://exchange.xforce.ibmcloud.com/vulnerabilities/15700 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1016 •
CVE-2004-0120 – Microsoft IIS - SSL Remote Denial of Service (MS04-011)
https://notcve.org/view.php?id=CVE-2004-0120
The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages. La librería Microsoft Secure Sockets Layer (SSL), usada en Windows 2000, Windows XP y Windows Server 2003, permite a atacantes remotos causar una denegación de servicio mediante mensajes SSL malformados. • https://www.exploit-db.com/exploits/176 http://www.ciac.org/ciac/bulletins/o-114.shtml http://www.kb.cert.org/vuls/id/150236 http://www.securityfocus.com/bid/10115 http://www.us-cert.gov/cas/techalerts/TA04-104A.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011 https://exchange.xforce.ibmcloud.com/vulnerabilities/15712 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A885 https://oval.cisecurity.org/repo •
CVE-2003-0908 – Microsoft Windows Utility Manager - Local Privilege Escalation (MS04-011)
https://notcve.org/view.php?id=CVE-2003-0908
The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213. Utility Manager enMicrosoft Windows 2000 ejecuta winhlp32.exe con privilegios de sistema, lo que permite a usuarios locales ejecutar código de su elección mediante un ataque de estilo "shatter" (hacer añícos) usando mensajes de Windows, como se ha demostrado usando el diálogo de apertura de ficheor en la ventana de ayuda. • https://www.exploit-db.com/exploits/271 http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0082.html http://www.appsecinc.com/resources/alerts/general/04-0001.html http://www.ciac.org/ciac/bulletins/o-114.shtml http://www.kb.cert.org/vuls/id/526084 http://www.securiteam.com/windowsntfocus/5LP0C2ACKU.html http://www.securityfocus.com/bid/10124 http://www.us-cert.gov/cas/techalerts/TA04-104A.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004 •