Search Results (Refine Search)
- CPE Product Version: cpe:/o:microsoft:windows_2000:-:sp4
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2004-0978 |
Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData parameter. Published: February 09, 2005; 12:00:00 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
CVE-2004-0213 |
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908. Published: August 06, 2004; 12:00:00 AM -0400 |
V3.1: 7.8 HIGH V2.0: 7.2 HIGH |