Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2001-10-30 CVE-2001-0665 Unspecified vulnerability in Microsoft IE
Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP Request Encoding vulnerability."
network
low complexity
microsoft
7.5
2001-10-30 CVE-2001-0664 Unspecified vulnerability in Microsoft Internet Explorer 5.01/5.5
Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing vulnerability."
network
low complexity
microsoft
7.5
2001-09-20 CVE-2001-0658 Cross-Site Scripting vulnerability in Microsoft ISA Server 2000
Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message.
network
low complexity
microsoft
7.5
2001-09-20 CVE-2001-0541 Buffer Overflow vulnerability in Microsoft Windows Media Player .NSC File
Buffer overflow in Microsoft Windows Media Player 7.1 and earlier allows remote attackers to execute arbitrary commands via a malformed Windows Media Station (.NSC) file.
network
low complexity
microsoft
7.5
2001-09-20 CVE-2001-0507 Unspecified vulnerability in Microsoft Internet Information Services 5.0
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.
local
low complexity
microsoft
7.2
2001-09-20 CVE-2001-0506 Buffer Overrun Privelege Elevation vulnerability in Microsoft products
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.
local
low complexity
microsoft
7.2
2001-09-12 CVE-2001-0999 Unspecified vulnerability in Microsoft Outlook Express 6.0
Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script.
network
low complexity
microsoft
7.5
2001-08-31 CVE-2001-1452 Origin Validation Error vulnerability in Microsoft Windows 2000 and Windows NT
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.
network
low complexity
microsoft CWE-346
7.5
2001-08-14 CVE-2001-0628 Unspecified vulnerability in Microsoft Word 2000
Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.
local
low complexity
microsoft
7.2
2001-08-14 CVE-2001-0504 Authentication vulnerability in Microsoft Windows 2000 SMTP Improper
Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activities such as mail relaying.
network
low complexity
microsoft
7.5