VendorsMicrosoftproject_server2003
Vulnerabilities

Microsoft Project Server 2003

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2009-0102
Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."
Published 2009-12-09 · Modified
9.3EPSS 0.235
CVE-2006-6617
projectserver/logon/pdsrequest.asp in Microsoft Project Server 2003 allows remote authenticated users to obtain the MSProjectUser password for a SQL database via a GetInitializationData request, which includes the information in the UserName and Password tags of the response.
Published 2006-12-18 · Modified
6.5EPSS 0.204