Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2001-07-21 CVE-2001-0346 Unspecified vulnerability in Microsoft Windows 2000
Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.
network
low complexity
microsoft
5.0
2001-07-21 CVE-2001-0345 Sessions DoS vulnerability in Microsoft Windows 2000 Telnet
Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.
network
low complexity
microsoft
5.0
2001-07-21 CVE-2001-0344 Unspecified vulnerability in Microsoft SQL Server 2000/7.0
An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.
local
low complexity
microsoft
7.2
2001-07-21 CVE-2001-0341 Buffer Overflow vulnerability in Microsoft products
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.
network
low complexity
microsoft
7.5
2001-07-21 CVE-2001-0340 Unrestricted Upload of File With Dangerous Type vulnerability in Microsoft Exchange Server 2000/5.5
An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
network
low complexity
microsoft CWE-434
7.5
2001-07-21 CVE-2001-0018 Unspecified vulnerability in Microsoft Windows 2000
Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests.
network
low complexity
microsoft
5.0
2001-07-21 CVE-2001-0002 Unspecified vulnerability in Microsoft Internet Explorer and Windows Script Host
Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.
network
low complexity
microsoft
7.5
2001-07-18 CVE-2001-1302 Unspecified vulnerability in Microsoft Windows 2000
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function.
local
low complexity
microsoft
2.1
2001-07-16 CVE-2001-1319 Denial of Service vulnerability in Microsoft Exchange 5.5 LDAP
Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.
network
low complexity
microsoft
5.0
2001-07-16 CVE-2001-1238 Improper Handling of Case Sensitivity vulnerability in Microsoft Windows 2000
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.
local
low complexity
microsoft CWE-178
7.8