Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2001-02-16 CVE-2001-0089 Unspecified vulnerability in Microsoft Internet Explorer
Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.
network
high complexity
microsoft
2.6
2001-02-16 CVE-2001-0047 Unspecified vulnerability in Microsoft Windows NT 4.0/Terminalserver
The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities.
network
low complexity
microsoft
7.5
2001-02-16 CVE-2001-0046 Unspecified vulnerability in Microsoft Windows 2000 and Windows NT
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.
local
low complexity
microsoft
4.6
2001-02-16 CVE-2001-0045 Unspecified vulnerability in Microsoft Windows NT 4.0/Terminalserver
The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.
network
low complexity
microsoft
critical
10.0
2001-02-12 CVE-2001-0096 Unspecified vulnerability in Microsoft products
FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.
network
low complexity
microsoft
5.0
2001-02-12 CVE-2001-0048 Unspecified vulnerability in Microsoft Windows 2000
The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.
local
low complexity
microsoft
7.2
2001-02-12 CVE-2001-0014 Unspecified vulnerability in Microsoft Windows 2000
Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.
network
low complexity
microsoft
5.0
2001-02-12 CVE-2001-0006 Incorrect Permission Assignment for Critical Resource vulnerability in Microsoft Windows NT 4.0
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.
local
low complexity
microsoft CWE-732
7.1
2001-02-12 CVE-2001-0005 Unspecified vulnerability in Microsoft Powerpoint 2000
Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.
local
high complexity
microsoft
6.2
2001-02-12 CVE-2001-0004 Unspecified vulnerability in Microsoft products
IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.
network
low complexity
microsoft
5.0