Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2001-12-31 CVE-2001-1547 Remote Security vulnerability in Microsoft Outlook Express 6.0
Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, does not block email attachments from forwarded messages, which could allow remote attackers to execute arbitrary code.
network
low complexity
microsoft
7.5
2001-12-31 CVE-2001-1515 Improper Preservation of Permissions vulnerability in Microsoft Windows 2000
Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended.
network
low complexity
microsoft CWE-281
7.5
2001-12-20 CVE-2001-0876 Buffer Overflow vulnerability in Microsoft UPnP NOTIFY
Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY directive with a long Location URL.
network
low complexity
microsoft
7.5
2001-12-20 CVE-2001-0542 Buffer Overflow vulnerability in Microsoft SQL-Server 2000/7.0
Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf.
network
low complexity
microsoft
7.5
2001-12-17 CVE-2001-1200 Unspecified vulnerability in Microsoft Windows XP
Microsoft Windows XP allows local users to bypass a locked screen and run certain programs that are associated with Hot Keys.
local
low complexity
microsoft
7.2
2001-12-14 CVE-2001-0727 Unspecified vulnerability in Microsoft Internet Explorer 5.5/6.0
Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability."
network
low complexity
microsoft
7.5
2001-12-06 CVE-2001-0860 Unspecified vulnerability in Microsoft Windows 2000 and Windows XP
Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g.
network
low complexity
microsoft
7.5
2001-12-06 CVE-2001-0726 Unspecified vulnerability in Microsoft Exchange Server 5.5
Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.
network
low complexity
microsoft
7.5
2001-12-06 CVE-2001-0719 Buffer Overflow vulnerability in Microsoft Windows Media Player 6.4
Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file.
network
low complexity
microsoft
7.5
2001-11-26 CVE-2001-0875 Unspecified vulnerability in Microsoft Internet Explorer 5.5/6.0
Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download.
network
low complexity
microsoft
7.5