Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2001-02-12 CVE-2001-0014 Unspecified vulnerability in Microsoft Windows 2000
Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.
network
low complexity
microsoft
5.0
2001-02-12 CVE-2001-0006 Incorrect Permission Assignment for Critical Resource vulnerability in Microsoft Windows NT 4.0
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.
local
low complexity
microsoft CWE-732
7.1
2001-02-12 CVE-2001-0005 Unspecified vulnerability in Microsoft Powerpoint 2000
Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.
local
high complexity
microsoft
6.2
2001-02-12 CVE-2001-0004 Unspecified vulnerability in Microsoft products
IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.
network
low complexity
microsoft
5.0
2001-02-12 CVE-2001-0003 Unspecified vulnerability in Microsoft products
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
network
low complexity
microsoft
5.0
2001-02-12 CVE-2000-1090 Unspecified vulnerability in Microsoft Internet Information Server 4.0/5.0
Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.
network
low complexity
microsoft
5.0
2001-01-09 CVE-2000-1149 Unspecified vulnerability in Microsoft Windows NT Terminalserver
Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the "Terminal Server Login Buffer Overflow" vulnerability.
network
low complexity
microsoft
7.5
2001-01-09 CVE-2000-1147 Buffer Overflow vulnerability in Microsoft Internet Information Server 4.0
Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a script tag.
local
low complexity
microsoft
4.6
2001-01-09 CVE-2000-1139 USE of Hard-Coded Credentials vulnerability in Microsoft Exchange Server 2000
The installation of Microsoft Exchange 2000 before Rev.
network
low complexity
microsoft CWE-798
7.5
2001-01-09 CVE-2000-1113 Unspecified vulnerability in Microsoft Windows Media Player 6.4/7
Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the ".ASX Buffer Overrun" vulnerability.
network
low complexity
microsoft
7.5