Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2001-07-21 CVE-2001-0349 Privilege Escalation vulnerability in Microsoft Windows 2000 Telnet
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.
local
low complexity
microsoft
7.2
2001-07-21 CVE-2001-0347 Unspecified vulnerability in Microsoft Windows 2000
Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.
network
low complexity
microsoft
7.5
2001-07-21 CVE-2001-0344 Unspecified vulnerability in Microsoft SQL Server 2000/7.0
An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.
local
low complexity
microsoft
7.2
2001-07-21 CVE-2001-0341 Buffer Overflow vulnerability in Microsoft products
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.
network
low complexity
microsoft
7.5
2001-07-21 CVE-2001-0340 Unrestricted Upload of File With Dangerous Type vulnerability in Microsoft Exchange Server 2000/5.5
An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
network
low complexity
microsoft CWE-434
7.5
2001-07-21 CVE-2001-0002 Unspecified vulnerability in Microsoft Internet Explorer and Windows Script Host
Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.
network
low complexity
microsoft
7.5
2001-07-16 CVE-2001-1238 Improper Handling of Case Sensitivity vulnerability in Microsoft Windows 2000
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.
local
low complexity
microsoft CWE-178
7.8
2001-07-02 CVE-2001-0239 Unspecified vulnerability in Microsoft ISA Server 2000
Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.
network
low complexity
microsoft
7.5
2001-07-02 CVE-2001-0238 Unspecified vulnerability in Microsoft products
Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.
network
low complexity
microsoft
7.5
2001-06-27 CVE-2001-0339 Unspecified vulnerability in Microsoft Internet Explorer
Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."
network
low complexity
microsoft
7.5