Popis service packova i sigurnosnih zakrpa za
Microsoftove operativne sisteme i aplikacije

Microsoft Windows 95 SR 2.5

MS02-006 : Unchecked Buffer in SNMP Service Could Enable Arbitrary Code to be Run
MS01-022 : WebDAV Service Provider Can Allow Scripts to Levy Requests as User
MS01-017 : Erroneous VeriSign-Issued Digital Certificates Pose Spoofing Hazard
MS00-073 : Malformed IPX NMPI Packet Vulnerability
MS00-054 : Malformed IPX Ping Packet Vulnerability
MS00-029 : IP Fragment Reassembly Vulnerability
MS00-017 : DOS Device in Path Name Vulnerability
MS00-005 : Malformed RTF Control Word Vulnerability
MS99-052 : Legacy Credential Caching Vulnerability
MS99-049 : File Access URL Vulnerability
MS99-033 : Malformed Telnet Argument Vulnerability
MS99-034 : Fragmented IGMP Packet Vulnerability
MS98-012 : Updates available for Security Vulnerabilities in Microsoft PPTP
MS98-010 : Information on the Back Orifice Program


Microsoft Windows 98 SE

MS05-015 : Vulnerability in Hyperlink Object Library Could Allow Remote Code Execution (888113)
MS05-014 : Cumulative Security Update for Internet Explorer (867282)
MS05-013 : Vulnerability in the DHTML Editing ActiveX Control could allow code execution (891781)
MS05-012 : Vulnerability in OLE and COM Could Allow Remote Code Execution (873333)
MS05-009 : Vulnerability in PNG Processing Could Lead to Buffer Overrun (890261)
MS05-002 : Vulnerability in Cursor and Icon Format Handling Could Allow Remote Code Execution (891711)
MS05-001 : Vulnerability in HTML Help Could Allow Code Execution (890175)
MS04-041 : Vulnerability in WordPad Could Allow Code Execution (885836)
MS04-032 : Security Update for Microsoft Windows (840987)
MS04-031 : Vulnerability in NetDDE Could Allow Remote Code Execution (841533)
MS04-024 : Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)
MS04-023 : Vulnerability in HTML Help Could Allow Code Execution (840315)
MS04-016 : Vulnerability in DirectPlay Could Allow Denial of Service (839643)
MS04-014 : Vulnerability in the Microsoft Jet Database Engine Could Allow Code Execution (837001)
MS04-013 : Cumulative Security Update for Outlook Express (837009)
MS03-030 : Unchecked Buffer in DirectX Could Enable System Compromise (819696)
MS03-023 : Buffer Overrun In HTML Converter Could Allow Code Execution (823559)
MS03-011 : Flaw in Microsoft VM Could Enable System Compromise (816093)
MS03-008 : Flaw in Windows Script Engine Could Allow Code Execution (814078)
MS02-069 : Flaw in Microsoft VM Could Enable System Compromise (810030)
MS02-065 : Buffer Overrun in Microsoft Data Access Components Could Lead to Code Execution (Q329414)
MS02-055 : Unchecked Buffer in Windows Help Facility Could Enable Code Execution (Q323255)
MS02-054 : Unchecked Buffer in File Decompression Functions Could Lead to Code Execution (Q329048)
MS02-053 : Buffer Overrun in SmartHTML Interpreter Could Allow Code Execution (Q324096)
MS02-050 : Certificate Validation Flaw Could Enable Identity Spoofing (Q328145)
MS02-048 : Flaw in Certificate Enrollment Control Could Allow Deletion of Digital Certificates (Q323172)
MS02-014 : Unchecked Buffer in Windows Shell Could Lead to Code Execution
MS02-013 : 04 March 2002 Cumulative VM Update
MS02-006 : Unchecked Buffer in SNMP Service Could Enable Arbitrary Code to be Run
MS01-059 : Unchecked Buffer in Universal Plug and Play Can Lead to System Compromise
MS01-054 : Invalid Universal Plug and Play Request Can Disrupt System Operation
MS01-022 : WebDAV Service Provider Can Allow Scripts to Levy Requests as User
MS01-019 : Passwords for Compressed Folders are Recoverable
MS01-017 : Erroneous VeriSign-Issued Digital Certificates Pose Spoofing Hazard
MS00-091 : Incomplete TCP/IP Packet Vulnerability
MS00-081 : New Variant of VM File Reading Vulnerability
MS00-079 : HyperTerminal Buffer Overflow Vulnerability
MS00-075 : Microsoft VM ActiveX Component Vulnerability
MS00-074 : WebTV for Windows Denial of Service Vulnerability
MS00-073 : Malformed IPX NMPI Packet Vulnerability
MS00-072 : Share Level Password Vulnerability
MS00-059 : Java VM Applet Vulnerability
MS00-054 : Malformed IPX Ping Packet Vulnerability
MS00-029 : IP Fragment Reassembly Vulnerability
MS00-017 : DOS Device in Path Name Vulnerability
MS00-011 : VM File Reading Vulnerability
MS00-005 : Malformed RTF Control Word Vulnerability
MS99-045 : Virtual Machine Verifier Vulnerability
MS99-034 : Fragmented IGMP Packet Vulnerability
MS99-033 : Malformed Telnet Argument Vulnerability
MS99-031 : Virtual Machine Sandbox Vulnerability
MS98-010 : Information on the Back Orifice Program


Microsoft Windows ME

MS05-015 : Vulnerability in Hyperlink Object Library Could Allow Remote Code Execution (888113)
MS05-014 : Cumulative Security Update for Internet Explorer (867282)
MS05-013 : Vulnerability in the DHTML Editing ActiveX Control could allow code execution (891781)
MS05-012 : Vulnerability in OLE and COM Could Allow Remote Code Execution (873333)
MS05-009 : Vulnerability in PNG Processing Could Lead to Buffer Overrun (890261)
MS05-002 : Vulnerability in Cursor and Icon Format Handling Could Allow Remote Code Execution (891711)
MS05-001 : Vulnerability in HTML Help Could Allow Code Execution (890175)
MS04-041 : Vulnerability in WordPad Could Allow Code Execution (885836)
MS04-038 : Cumulative Security Update for Internet Explorer (834707)
MS04-024 : Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)
MS04-023 : Vulnerability in HTML Help Could Allow Code Execution (840315)
MS04-016 : Vulnerability in DirectPlay Could Allow Denial of Service (839643)
MS04-014 : Vulnerability in the Microsoft Jet Database Engine Could Allow Code Execution (837001)
MS04-013 : Cumulative Security Update for Outlook Express (837009)
MS03-030 : Unchecked Buffer in DirectX Could Enable System Compromise (819696)
MS03-023 : Buffer Overrun In HTML Converter Could Allow Code Execution (823559)
MS03-011 : Flaw in Microsoft VM Could Enable System Compromise (816093)
MS03-008 : Flaw in Windows Script Engine Could Allow Code Execution (814078)
MS03-006 : Flaw in Windows Me Help and Support Center Could Enable Code Execution (812709)
MS02-069 : Flaw in Microsoft VM Could Enable System Compromise (810030)
MS02-065 : Buffer Overrun in Microsoft Data Access Components Could Lead to Code Execution (Q329414)
MS02-055 : Unchecked Buffer in Windows Help Facility Could Enable Code Execution (Q323255)
MS02-054 : Unchecked Buffer in File Decompression Functions Could Lead to Code Execution (Q329048)
MS02-050 : Certificate Validation Flaw Could Enable Identity Spoofing (Q328145)
MS02-048 : Flaw in Certificate Enrollment Control Could Allow Deletion of Digital Certificates (Q323172)
MS02-013 : 04 March 2002 Cumulative VM Update
MS01-059 : Unchecked Buffer in Universal Plug and Play Can Lead to System Compromise
MS01-054 : Invalid Universal Plug and Play Request Can Disrupt System Operation
MS01-022 : WebDAV Service Provider Can Allow Scripts to Levy Requests as User
MS01-019 : Passwords for Compressed Folders are Recoverable
MS01-017 : Erroneous VeriSign-Issued Digital Certificates Pose Spoofing Hazard
MS01-001 : Web Client Will Perform NTLM Authentication Regardless of Security Settings
MS00-091 : Incomplete TCP/IP Packet Vulnerability
MS00-081 : New Variant of VM File Reading Vulnerability
MS00-079 : HyperTerminal Buffer Overflow Vulnerability
MS00-075 : Microsoft VM ActiveX Component Vulnerability
MS00-074 : WebTV for Windows Denial of Service Vulnerability
MS00-073 : Malformed IPX NMPI Packet Vulnerability
MS00-072 : Share Level Password Vulnerability
MS00-059 : Java VM Applet Vulnerability
MS00-011 : VM File Reading Vulnerability


Microsoft Windows NT Server 4.0 + SP6A

MS05-014 : Cumulative Security Update for Internet Explorer (867282)
MS05-010 : Vulnerability in the License Logging Service Could Allow Code Execution (885834)
MS05-002 : Vulnerability in Cursor and Icon Format Handling Could Allow Remote Code Execution (891711)
MS05-001 : Vulnerability in HTML Help Could Allow Code Execution (890175)
MS04-045 : Vulnerability in WINS Could Allow Remote Code Execution (870763)
MS04-044 : Vulnerabilities in Windows Kernel and LSASS Could Allow Elevation of Privilege (885835)
MS04-043 : Vulnerability in HyperTerminal Could Allow Code Execution (873339)
MS04-042 : Vulnerability in DHCP Could Allow Remote Code Execution and Denial Of Service (885249)
MS04-041 : Vulnerability in WordPad Could Allow Code Execution (885836)
MS04-040 : Cumulative Security Update for Internet Explorer (889293)
MS04-038 : Cumulative Security Update for Internet Explorer (834707)
MS04-037 : Vulnerability in Windows Shell Could Allow Remote Code Execution (841356)
MS04-036 : Vulnerability in NNTP Could Allow Code Execution (883935)
MS04-032 : Security Update for Microsoft Windows (840987)
MS04-031 : Vulnerability in NetDDE Could Allow Remote Code Execution (841533)
MS04-029 : Vulnerability in RPC Runtime Library Could Allow Information Disclosure and Denial of Service (873350)
MS04-028 : Buffer Overrun in JPEG Processing (GDI+) Could Allow Code Execution (873374)
MS04-025 : Cumulative Security Update for Internet Explorer (867801)
MS04-024 : Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)
MS04-023 : Vulnerability in HTML Help Could Allow Code Execution (840315)
MS04-022 : Vulnerability in Task Scheduler Could Allow Code Execution (841873)
MS04-021 : Security Update for IIS 4.0 (841373)
MS04-020 : Vulnerability in POSIX Could Allow Code Execution (841872)
MS04-014 : Vulnerability in the Microsoft Jet Database Engine Could Allow Code Execution (837001)
MS04-012 : Cumulative Update for Microsoft RPC/DCOM (828741)
MS04-011 : Security Update for Microsoft Windows (835732)
MS04-006 : Vulnerability in the Windows Internet Naming Service (WINS) Could Allow Code Execution (830352)
MS04-004 : Cumulative Security Update for Internet Explorer (832894)
MS03-045 : Buffer Overrun in the ListBox and in the ComboBox Control Could Allow Code Execution (824141)
MS03-044 : Buffer Overrun in Windows Help and Support Center Could Lead to System Compromise (825119)
MS03-043 : Buffer Overrun in Messenger Service Could Allow Code Execution (828035)
MS03-041 : Vulnerability in Authenticode Verification Could Allow Remote Code Execution (823182)
MS03-039 : Buffer Overrun In RPCSS Service Could Allow Code Execution (824146)
MS03-034 : Flaw in NetBIOS Could Lead to Information Disclosure (824105)
MS03-030 : Unchecked Buffer in DirectX Could Enable System Compromise (819696)
MS03-029 : Flaw in Windows Function Could Allow Denial of Service (823803)
MS03-026 : Buffer Overrun In RPC Interface Could Allow Code Execution (823980)
MS03-024 : Buffer Overrun in Windows Could Lead to Data Corruption (817606)
MS03-023 : Buffer Overrun In HTML Converter Could Allow Code Execution (823559)
MS03-019 : Flaw in ISAPI extension for Windows Media Services could cause denial of service (817772)
MS03-013 : Buffer Overrun in Windows Kernel Message Handling could Lead to Elevated Privileges (811493)
MS03-011 : Flaw in Microsoft VM Could Enable System Compromise (816093)
MS03-010 : Flaw in RPC Endpoint Mapper Could Allow Denial of Service Attacks (331953)
MS03-008 : Flaw in Windows Script Engine Could Allow Code Execution (814078)
MS03-007 : Unchecked Buffer In Windows Component Could Cause Server Compromise (815021)
MS03-001 : Unchecked Buffer in Locator Service Could Lead to Code Execution (810833)
MS02-071 : Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation (328310)
MS02-069 : Flaw in Microsoft VM Could Enable System Compromise (810030)
MS02-065 : Buffer Overrun in Microsoft Data Access Components Could Lead to Code Execution (Q329414)
MS02-055 : Unchecked Buffer in Windows Help Facility Could Enable Code Execution (Q323255)
MS02-053 : Buffer Overrun in SmartHTML Interpreter Could Allow Code Execution (Q324096)
MS02-050 : Certificate Validation Flaw Could Enable Identity Spoofing (Q328145)
MS02-048 : Flaw in Certificate Enrollment Control Could Allow Deletion of Digital Certificates (Q323172)
MS02-045 : Unchecked Buffer in Network Share Provider can lead to Denial of Service (Q326830)
MS02-029 : Unchecked Buffer in Remote Access Service Phonebook Could Lead to Code Execution (Q318138)
MS02-024 : Authentication Flaw in Windows Debugger Can Lead to Elevated Privileges (Q320206)
MS02-017 : Unchecked Buffer in the Multiple UNC Provider Could Enable Code Execution (Q311967)
MS02-014 : Unchecked Buffer in Windows Shell Could Lead to Code Execution
MS02-013 : 04 March 2002 Cumulative VM Update
MS02-008 : XMLHTTP Control Can Allow Access to Local Files
MS02-006 : Unchecked Buffer in SNMP Service Could Enable Arbitrary Code to be Run
MS01-048 : Malformed Request to RPC Endpoint Mapper Can Cause RPC Service to Fail
MS01-043 : NNTP Service in Windows NT 4.0 and Windows 2000 Contains Memory Leak
Windows NT 4.0 Post-Service Pack 6a Security Rollup Package
MS01-041 : Malformed RPC Request Can Cause Service Failure
MS01-022 : WebDAV Service Provider Can Allow Scripts to Levy Requests as User
MS01-017 : Erroneous VeriSign-Issued Digital Certificates Pose Spoofing Hazard
MS01-009 : Malformed PPTP Packet Stream Can Cause Kernel Exhaustion
MS01-008 : Malformed NTLMSSP Request Can Enable Code to Run with System Privileges
MS01-003 : Weak Permissions on Winsock Mutex Can Allow Service Failure
MS00-095 : Registry Permissions Vulnerability
MS00-094 : Phone Book Service Buffer Overflow Vulnerability
MS00-091 : Incomplete TCP/IP Packet Vulnerability
MS00-084 : Indexing Services Cross Site Scripting Vulnerability
MS00-083 : Netmon Protocol Parsing Vulnerability
MS00-081 : New Variant of VM File Reading Vulnerability
MS00-079 : HyperTerminal Buffer Overflow Vulnerability
MS00-075 : Microsoft VM ActiveX Component Vulnerability
MS00-070 : Multiple LPC and LPC Ports Vulnerabilities
MS00-063 : Invalid URL Vulnerability
MS00-059 : Java VM Applet Vulnerability
MS00-052 : Relative Shell Path Vulnerability
MS00-047 : NetBIOS Name Server Protocol Spoofing Vulnerability
MS00-040 : Remote Registry Access Authentication Vulnerability
MS00-036 : ResetBrowser Frame and Host Announcement Frame Vulnerabilities
MS00-029 : IP Fragment Reassembly Vulnerability
MS00-027 : Malformed Environment Variable Vulnerability
MS00-024 : OffloadModExpo Registry Permissions Vulnerability
MS00-021 : Malformed TCP/IP Print Request Vulnerability
MS00-008 : Registry Permissions Vulnerability
MS00-011 : VM File Reading Vulnerability
MS00-007 : Recycle Bin Creation Vulnerability
MS00-004 : RDISK Registry Enumeration File Vulnerability
MS00-005 : Malformed RTF Control Word Vulnerability
MS00-003 : Spoofed LPC Port Request Vulnerability
MS99-057 : Malformed Security Identifier Request Vulnerability
MS99-056 : Syskey Keystream Reuse Vulnerability
MS99-055 : Malformed Resource Enumeration Argument Vulnerability
MS99-047 : Malformed Spooler Request Vulnerability
MS99-046 : Improve TCP Initial Sequence Number Randomness
MS99-045 : Virtual Machine Verifier Vulnerability
MS99-041 : RASMAN Security Descriptor Vulnerability
MS99-036 : Windows NT 4.0 Does Not Delete Unattended Installation File
MS99-031 : Virtual Machine Sandbox Vulnerability
MS98-001 : Disabling Creation of Local Groups on a Domain by Non-Administrative Users


Microsoft Windows 2000 server + SP4

MS05-015 : Vulnerability in Hyperlink Object Library Could Allow Remote Code Execution (888113)
MS05-014 : Cumulative Security Update for Internet Explorer (867282)
MS05-013 : Vulnerability in the DHTML Editing ActiveX Control could allow code execution (891781)
MS05-012 : Vulnerability in OLE and COM Could Allow Remote Code Execution (873333)
MS05-011 : Vulnerability in Server Message Block Could Allow Remote Code Execution (885250)
MS05-010 : Vulnerability in the License Logging Service Could Allow Code Execution (885834)
MS05-009 : Vulnerability in PNG Processing Could Lead to Buffer Overrun (890261)
MS05-008 : Vulnerabilty in Windows Shell Could Allow Remote Code Execution (890047)
MS05-004 : ASP.NET Path Validation Vulnerability (887219)
MS05-003 : Vulnerability in the Indexing Service Could Allow Remote Code Execution (871250)
MS05-002 : Vulnerability in Cursor and Icon Format Handling Could Allow Remote Code Execution (891711)
MS05-001 : Vulnerability in HTML Help Could Allow Code Execution (890175)
MS04-045 : Vulnerability in WINS Could Allow Remote Code Execution (870763)
MS04-044 : Vulnerabilities in Windows Kernel and LSASS Could Allow Elevation of Privilege (885835)
MS04-043 : Vulnerability in HyperTerminal Could Allow Code Execution (873339)
MS04-041 : Vulnerability in WordPad Could Allow Code Execution (885836)
MS04-037 : Vulnerability in Windows Shell Could Allow Remote Code Execution (841356)
MS04-036 : Vulnerability in NNTP Could Allow Code Execution (883935)
MS04-032 : Security Update for Microsoft Windows (840987)
MS04-031 : Vulnerability in NetDDE Could Allow Remote Code Execution (841533)
MS04-030 : Vulnerability in WebDav XML Message Handler Could Lead to a Denial of Service (824151)
MS04-024 : Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)
MS04-023 : Vulnerability in HTML Help Could Allow Code Execution (840315)
MS04-022 : Vulnerability in Task Scheduler Could Allow Code Execution (841873)
MS04-020 : Vulnerability in POSIX Could Allow Code Execution (841872)
MS04-019 : Vulnerability in Utility Manager Could Allow Code Execution (842526)
MS04-016 : Vulnerability in DirectPlay Could Allow Denial of Service (839643)
MS04-014 : Vulnerability in the Microsoft Jet Database Engine Could Allow Code Execution (837001)
MS04-012 : Cumulative Update for Microsoft RPC/DCOM (828741)
MS04-011 : Security Update for Microsoft Windows (835732)
MS04-008 : Vulnerability in Windows Media Services Could Allow a Denial of Service (832359)
MS04-006 : Vulnerability in the Windows Internet Naming Service (WINS) Could Allow Code Execution (830352)
MS03-049 : Buffer Overrun in the Workstation Service Could Allow Code Execution (828749)
MS03-044 : Buffer Overrun in Windows Help and Support Center Could Lead to System Compromise (825119)
MS03-043 : Buffer Overrun in Messenger Service Could Allow Code Execution (828035)
MS03-042 : Buffer Overflow in Windows Troubleshooter ActiveX Control Could Allow Code Execution (826232)
MS03-041 : Vulnerability in Authenticode Verification Could Allow Remote Code Execution (823182)
MS03-034 : Flaw in NetBIOS Could Lead to Information Disclosure (824105)
MS03-023 : Buffer Overrun In HTML Converter Could Allow Code Execution (823559)
MS03-022 : Flaw in ISAPI Extension for Windows Media Services Could Cause Code Execution (822343)


Microsoft Windows Server 2003 Standard Edition

MS05-015 : Vulnerability in Hyperlink Object Library Could Allow Remote Code Execution (888113)
MS05-014 : Cumulative Security Update for Internet Explorer (867282)
MS05-013 : Vulnerability in the DHTML Editing ActiveX Control could allow code execution (891781)
MS05-012 : Vulnerability in OLE and COM Could Allow Remote Code Execution (873333)
MS05-011 : Vulnerability in Server Message Block Could Allow Remote Code Execution (885250)
MS05-010 : Vulnerability in the License Logging Service Could Allow Code Execution (885834)
MS05-009 : Vulnerability in PNG Processing Could Lead to Buffer Overrun (890261)
MS05-008 : Vulnerabilty in Windows Shell Could Allow Remote Code Execution (890047)
MS05-004 : ASP.NET Path Validation Vulnerability (887219)
MS05-003 : Vulnerability in the Indexing Service Could Allow Remote Code Execution (871250)
MS05-002 : Vulnerability in Cursor and Icon Format Handling Could Allow Remote Code Execution (891711)
MS05-001 : Vulnerability in HTML Help Could Allow Code Execution (890175)
MS04-045 : Vulnerability in WINS Could Allow Remote Code Execution (870763)
MS04-044 : Vulnerabilities in Windows Kernel and LSASS Could Allow Elevation of Privilege (885835)
MS04-043 : Vulnerability in HyperTerminal Could Allow Code Execution (873339)
MS04-041 : Vulnerability in WordPad Could Allow Code Execution (885836)
MS04-037 : Vulnerability in Windows Shell Could Allow Remote Code Execution (841356)
MS04-036 : Vulnerability in NNTP Could Allow Code Execution (883935)
MS04-035 : Vulnerability in SMTP Could Allow Remote Code Execution (885881)
MS04-034 : Vulnerability in Compressed (zipped) Folders Could Allow Code Execution (873376)
MS04-032 : Security Update for Microsoft Windows (840987)
MS04-031 : Vulnerability in NetDDE Could Allow Remote Code Execution (841533)
MS04-030 : Vulnerability in WebDav XML Message Handler Could Lead to a Denial of Service (824151)
MS04-028 : Buffer Overrun in JPEG Processing (GDI+) Could Allow Code Execution (873374)
MS04-024 : Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)
MS04-023 : Vulnerability in HTML Help Could Allow Code Execution (840315)
MS04-016 : Vulnerability in DirectPlay Could Allow Denial of Service (839643)
MS04-015 : Vulnerability in Help and Support Center Could Allow Remote Code Execution (840374)
MS04-014 : Vulnerability in the Microsoft Jet Database Engine Could Allow Code Execution (837001)
MS04-012 : Cumulative Update for Microsoft RPC/DCOM (828741)
MS04-011 : Security Update for Microsoft Windows (835732)
MS04-006 : Vulnerability in the Windows Internet Naming Service (WINS) Could Allow Code Execution (830352)
MS04-004 : Cumulative Security Update for Internet Explorer (832894)
MS04-003 : Buffer Overrun in MDAC Function Could Allow Code Execution (832483)
MS03-045 : Buffer Overrun in the ListBox and in the ComboBox Control Could Allow Code Execution (824141)
MS03-044 : Buffer Overrun in Windows Help and Support Center Could Lead to System Compromise (825119)
MS03-043 : Buffer Overrun in Messenger Service Could Allow Code Execution (828035)
MS03-041 : Vulnerability in Authenticode Verification Could Allow Remote Code Execution (823182)
MS03-039 : Buffer Overrun In RPCSS Service Could Allow Code Execution (824146)
MS03-034 : Flaw in NetBIOS Could Lead to Information Disclosure (824105)
MS03-030 : Unchecked Buffer in DirectX Could Enable System Compromise (819696)
MS03-026 : Buffer Overrun In RPC Interface Could Allow Code Execution (823980)
MS03-023 : Buffer Overrun In HTML Converter Could Allow Code Execution (823559)


Microsoft Windows XP Professional + SP2

MS05-015 : Vulnerability in Hyperlink Object Library Could Allow Remote Code Execution (888113)
MS05-014 : Cumulative Security Update for Internet Explorer (867282)
MS05-013 : Vulnerability in the DHTML Editing ActiveX Control could allow code execution (891781)
MS05-012 : Vulnerability in OLE and COM Could Allow Remote Code Execution (873333)
MS05-011 : Vulnerability in Server Message Block Could Allow Remote Code Execution (885250)
MS05-009 : Vulnerability in PNG Processing Could Lead to Buffer Overrun (890261)
MS05-008 : Vulnerabilty in Windows Shell Could Allow Remote Code Execution (890047)
MS05-007 : Vulnerability in Windows Could Allow Information Disclosure (888302)
MS05-004 : ASP.NET Path Validation Vulnerability (887219)
MS05-001 : Vulnerability in HTML Help Could Allow Code Execution (890175)
MS04-044 : Vulnerabilities in Windows Kernel and LSASS Could Allow Elevation of Privilege (885835)
MS04-043 : Vulnerability in HyperTerminal Could Allow Code Execution (873339)
MS04-041 : Vulnerability in WordPad Could Allow Code Execution (885836)
MS03-011 : Flaw in Microsoft VM Could Enable System Compromise (816093)


Microsoft Internet Explorer 5.01 + SP4 (samo Windows 2000)

MS05-014 : Cumulative Security Update for Internet Explorer (867282)
MS04-025 : Cumulative Security Update for Internet Explorer (867801)


Microsoft Internet Explorer 5.5 + SP2 (samo Window ME)

MS04-038 : Cumulative Security Update for Internet Explorer (834707)
MS04-025 : Cumulative Security Update for Internet Explorer (867801)
MS02-009 : Incorrect VBScript Handling in IE Can Allow Web Pages to Read Local Files


Microsoft Internet Explorer 6.0 + SP1

MS05-014 : Cumulative Security Update for Internet Explorer (867282)
MS05-001 : Vulnerability in HTML Help Could Allow Code Execution (890175)
MS04-028 : Buffer Overrun in JPEG Processing (GDI+) Could Allow Code Execution (873374)
MS04-023 : Vulnerability in HTML Help Could Allow Code Execution (840315)
MS04-022 : Vulnerability in Task Scheduler Could Allow Code Execution (841873)


Microsoft Internet Explorer 6.0 for Windows XP SP2

MS05-014 : Cumulative Security Update for Internet Explorer (867282)


Microsoft Internet Explorer 6.0 for Windows server 2003

MS05-014 : Cumulative Security Update for Internet Explorer (867282)
MS03-048 : Cumulative Security Update for Internet Explorer (824145)


Microsoft Exchange server 5.5 + SP4

MS05-012 : Vulnerability in OLE and COM Could Allow Remote Code Execution (873333)
MS04-026 : Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow Cross-Site Scripting and Spoofing Attacks (842463)
MS03-047 : Vuln. in Exchange Server 5.5 Outlook Web Access Could Allow Cross-Site Scripting Attack (828489)
MS03-046 : Vulnerability in Exchange Server Could Allow Arbitrary Code Execution (822363)
MS02-037 : Server Response To SMTP Client EHLO Command Results In Buffer Overrun (Q326322)
MS02-011 : Authentication Flaw Could Allow Unauthorized Users To Authenticate To SMTP Service
MS01-047 : OWA Function Allows Unauthenticated User to Enumerate Global Address List
MS01-041 : Malformed RPC Request Can Cause Service Failure


Microsoft Exchange 2000 server + SP3

MS05-012 : Vulnerability in OLE and COM Could Allow Remote Code Execution (873333)
MS04-036 : Vulnerability in NNTP Could Allow Code Execution (883935)
MS04-035 : Vulnerability in SMTP Could Allow Remote Code Execution (885881)
MS03-046 : Vulnerability in Exchange Server Could Allow Arbitrary Code Execution (822363)


Microsoft Exchange 2003 server + SP1

MS05-012 : Vulnerability in OLE and COM Could Allow Remote Code Execution (873333)


Microsoft SQL server 7.0 + SP4

MS03-031 : Cumulative Patch for Microsoft SQL Server (815495)
MS02-040 : Unchecked Buffer in MDAC Function Could Enable SQL Server Compromise (Q326573)
MS02-035 : SQL Server Installation Process May Leave Passwords on System (Q263968)


Microsoft SQL server 2000 + SP3a

MS04-003 : Buffer Overrun in MDAC Function Could Allow Code Execution (832483)
MS03-031 : Cumulative Patch for Microsoft SQL Server (815495)


Microsoft Office 2000 + SP3

MS04-033 : Vulnerability in Microsoft Excel Could Allow Code Execution (886836)
MS04-027 : Vulnerability in WordPerfect Converter Could Allow Code Execution (884933)
MS03-050 : Vulnerability in Microsoft Word and Microsoft Excel Could Allow Arbitrary Code to run. (831527)
MS03-037 : Flaw in Visual Basic for Applications Could Allow Arbitrary Code execution (822715)
MS03-035 : Flaw in Microsoft Word Could Enable Macros to Run Automatically (827653)


Microsoft Office XP + SP3

MS05-012 : Vulnerability in OLE and COM Could Allow Remote Code Execution (873333)
MS05-005 : Vulnerability in Microsoft Office XP could lead to Buffer Overrun (873352)
MS04-028 : Buffer Overrun in JPEG Processing (GDI+) Could Allow Code Execution (873374)
MS04-027 : Vulnerability in WordPerfect Converter Could Allow Code Execution (884933)


Microsoft Office 2003 + SP1

MS05-012 : Vulnerability in OLE and COM Could Allow Remote Code Execution (873333)


Microsoft Internet Information server 4.0
Windows NT 4.0 + SP6a

MS04-021 : Security Update for IIS 4.0 (841373)
MS03-018 : Cumulative Patch for Internet Information Service (811114)
MS00-028 : Server-Side Image Map Components Vulnerability
MS00-025 : Link View Server-Side Component Vulnerability
MS00-019 : Virtualized UNC Share Vulnerability
MS99-025 : Unauthorized Access to IIS Servers through ODBC Data Access with RDS


Microsoft Internet Information services 5.0
Windows 2000 Server + SP4

MS04-030 : Vulnerability in WebDav XML Message Handler Could Lead to a Denial of Service (824151)


Microsoft Internet Information Services 5.1
Windows XP Pro + SP1

MS04-030 : Vulnerability in WebDav XML Message Handler Could Lead to a Denial of Service (824151)
MS03-018 : Cumulative Patch for Internet Information Service (811114)


Microsoft Internet Information services 6.0
Windows 2003

MS04-030 : Vulnerability in WebDav XML Message Handler Could Lead to a Denial of Service (824151)


Microsoft ISA server 2000 + SP2

Vulnerability in ISA Server 2000 and Proxy Server 2.0 Could Allow Internet Content Spoofing (888258)

Objašnjenje

Navedena je zadnja verzija operativnog sistema ili aplikacije koju preporučujemo svojim korisnicima. Nakon instaliranja operativnog sistema / aplikacije treba instalirati i preporučeni service pack, a na kraju primijeniti i sve zakrpe iz popisa ispod naslova instaliranog programa.

Primjer

Windows NT 4.0: na navedenu verziju operativnog sistema treba instalirati zadnji service pack (SP6a) i nakon toga primijeniti svih 70-tak zakrpa. Windows 95 SR 2.5: ako je i potrebno koristiti Windows 95, preporučujemo da to bude verzija SR 2.5.

Ostalo

Ovaj popis je preporuka sa gledišta zaštite sustava primjenom zakrpa za registrirane sigurnosne propuste. Prije primjene service packa ili zakrpe obavezno provjerite da li koja od njih dovodi do kasnijih problema u radu, te da li je u potpunosti kompatibilna sa drugim operativnim sistemima ili aplikacijama koje koristite na mreži, bez obzira na proizvođača. Preporučujemo da svaki service pack i zakrpu prvo detaljno testirate na odvojenom sustavu, a na proizvodnom sustavu ju primijenite tek nakon uspješno zavšenih testova. Također je potrebno dodatno provjeriti na stranicama Microsofta da li postoje zakrpe za odvojene aplikacije koje su sastavni dio nekih paketa (npr. zakrpe za MSOffice ne pokrivaju sve zakrpe neophodne pojedinim aplikacijama u tom paketu).

Qubis d.o.o. održava popis s najboljom namjerom pomaganja svojim korisnicima u povećanju zaštite informatičkog sustava, ali ne može preuzeti odgovornost za štetu nastalu primjenom navedenih zakrpa. Popis je napravljen na temelju analize Microsoftove stranice HotFix & Bulletin Search, a konačni podaci se mogu naći na navedenim stranicama. Tijekom testiranja Qubis je analizirao programe WindowsUpdate, HFNetChk i Microsoft Baseline Security Analyzer (više podataka možete pronaći na stranicama Microsofta), no ustanovljeno je da se predloženi popis zakrpa ponekad razlikuje od programa do programa, pa su kao najpouzdaniji izvor ipak odabrane gornje usluge.
_____
©2003-2004 Qubis ... Zadnja promjena: 21.02.2005