Vulnerabilities > Microsoft
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2000-10-20 | CVE-2000-0777 | Unspecified vulnerability in Microsoft Money 2000/2001 The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability. | 7.2 |
2000-10-20 | CVE-2000-0771 | Unspecified vulnerability in Microsoft Windows 2000 Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability. | 2.1 |
2000-10-20 | CVE-2000-0770 | Unspecified vulnerability in Microsoft products IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability. | 6.4 |
2000-10-20 | CVE-2000-0768 | Unspecified vulnerability in Microsoft IE and Internet Explorer A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability. | 2.6 |
2000-10-20 | CVE-2000-0767 | Unspecified vulnerability in Microsoft Internet Explorer The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability. | 2.6 |
2000-10-20 | CVE-2000-0765 | Unspecified vulnerability in Microsoft Excel, Powerpoint and Word Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability. | 5.1 |
2000-10-20 | CVE-2000-0753 | Unspecified vulnerability in Microsoft Outlook 2000/97/98 The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files. | 5.0 |
2000-10-20 | CVE-2000-0742 | Unspecified vulnerability in Microsoft Windows 95 and Windows 98 The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability. | 5.0 |
2000-10-20 | CVE-2000-0737 | Unspecified vulnerability in Microsoft Windows 2000 The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability. | 4.6 |
2000-10-20 | CVE-2000-0710 | Denial Of Service vulnerability in Microsoft FrontPage Server Extensions MS-DOS Device Name The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name. | 5.0 |