Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2001-12-07 CVE-2001-0951 Unspecified vulnerability in Microsoft Windows 2000
Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (IKE) UDP port 500 with packets that contain a large number of dot characters.
network
low complexity
microsoft
5.0
2001-12-06 CVE-2001-0860 Unspecified vulnerability in Microsoft Windows 2000 and Windows XP
Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g.
network
low complexity
microsoft
7.5
2001-12-06 CVE-2001-0807 Unspecified vulnerability in Microsoft Internet Explorer 5.0
Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file.
network
high complexity
microsoft
2.6
2001-12-06 CVE-2001-0726 Unspecified vulnerability in Microsoft Exchange Server 5.5
Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.
network
low complexity
microsoft
7.5
2001-12-06 CVE-2001-0722 Unspecified vulnerability in Microsoft Internet Explorer 5.5/6.0
Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."
network
low complexity
microsoft
6.4
2001-12-06 CVE-2001-0721 Unspecified vulnerability in Microsoft products
Universal Plug and Play (UPnP) in Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service (memory consumption or crash) via a malformed UPnP request.
network
low complexity
microsoft
5.0
2001-12-06 CVE-2001-0719 Buffer Overflow vulnerability in Microsoft Windows Media Player 6.4
Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file.
network
low complexity
microsoft
7.5
2001-12-06 CVE-2001-0663 Unspecified vulnerability in Microsoft Windows 2000 and Windows NT
Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.
network
low complexity
microsoft
5.0
2001-12-03 CVE-2001-0945 Buffer Overflow vulnerability in Microsoft Outlook Express 5.0/5.0.1/5.0.2
Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line.
network
low complexity
microsoft
5.0
2001-11-26 CVE-2001-0919 Unspecified vulnerability in Microsoft Internet Explorer 5.5
Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript.
network
high complexity
microsoft
5.1