Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2000-11-14 CVE-2000-0851 Unspecified vulnerability in Microsoft Windows 2000
Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the "Still Image Service Privilege Escalation" vulnerability.
local
low complexity
microsoft
4.6
2000-11-14 CVE-2000-0849 Unspecified vulnerability in Microsoft Windows Media Services 4.0/4.1
Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.
network
high complexity
microsoft
2.6
2000-11-14 CVE-2000-0834 Unspecified vulnerability in Microsoft Windows 2000
The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability.
network
low complexity
microsoft
7.5
2000-11-14 CVE-2000-0830 Unspecified vulnerability in Microsoft Webtv
annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP packet to ports 22701 through 22705.
network
low complexity
microsoft
5.0
2000-10-20 CVE-2000-0777 Unspecified vulnerability in Microsoft Money 2000/2001
The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability.
local
low complexity
microsoft
7.2
2000-10-20 CVE-2000-0771 Unspecified vulnerability in Microsoft Windows 2000
Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.
local
low complexity
microsoft
2.1
2000-10-20 CVE-2000-0770 Unspecified vulnerability in Microsoft products
IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability.
network
low complexity
microsoft
6.4
2000-10-20 CVE-2000-0768 Unspecified vulnerability in Microsoft IE and Internet Explorer
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.
network
high complexity
microsoft
2.6
2000-10-20 CVE-2000-0767 Unspecified vulnerability in Microsoft Internet Explorer
The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability.
network
high complexity
microsoft
2.6
2000-10-20 CVE-2000-0765 Unspecified vulnerability in Microsoft Excel, Powerpoint and Word
Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.
network
high complexity
microsoft
5.1