Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2002-07-03 CVE-2002-0615 Unspecified vulnerability in Microsoft Excel and Office
The Windows Media Active Playlist in Microsoft Windows Media Player 7.1 stores information in a well known location on the local file system, allowing attackers to execute HTML scripts in the Local Computer zone, aka "Media Playback Script Invocation".
network
low complexity
microsoft
7.5
2002-07-03 CVE-2002-0373 Privilege Escalation vulnerability in Microsoft Windows Media Player 7.1
The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Privilege Elevation through Windows Media Device Manager Service".
local
low complexity
microsoft
7.2
2002-07-03 CVE-2002-0372 Path Disclosure vulnerability in Windows Media Player IE Cache
Microsoft Windows Media Player versions 6.4 and 7.1 and Media Player for Windows XP allow remote attackers to bypass Internet Explorer's (IE) security mechanisms and run code via an executable .wma media file with a license installation requirement stored in the IE cache, aka the "Cache Path Disclosure via Windows Media Player".
network
low complexity
microsoft
7.5
2002-07-03 CVE-2002-0371 Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
network
low complexity
microsoft university-of-minnesota
7.5
2002-07-03 CVE-2002-0366 Remote Access Service Buffer Overflow vulnerability in Microsoft Windows 2000, Windows NT and Windows XP
Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.
local
low complexity
microsoft
7.2
2002-07-03 CVE-2002-0364 Heap Overflow vulnerability in Microsoft products
Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."
network
low complexity
microsoft
7.5
2002-07-03 CVE-2002-0187 Unspecified vulnerability in Microsoft SQL Server 2000
Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."
network
low complexity
microsoft
7.5
2002-07-03 CVE-2002-0186 Buffer Overflow vulnerability in Microsoft SQL Server 2000
Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."
network
low complexity
microsoft
7.5
2002-06-25 CVE-2002-0367 Unspecified vulnerability in Microsoft Windows 2000 and Windows NT
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
local
low complexity
microsoft
7.8
2002-06-25 CVE-2002-0340 Unspecified vulnerability in Microsoft Windows Media Player
Windows Media Player (WMP) 8.00.00.4477, and possibly other versions, automatically detects and executes .wmf and other content, even when the file's extension or content type does not specify .wmf, which could make it easier for attackers to conduct unauthorized activities via Trojan horse files containing .wmf content.
network
low complexity
microsoft
7.5