Vulnerabilities > Microsoft > Windows 2000

DATE CVE VULNERABILITY TITLE RISK
2008-04-08 CVE-2008-0083 Code Injection vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors.
network
microsoft CWE-94
critical
9.3
2008-03-25 CVE-2008-1092 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Word
Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008.
network
microsoft CWE-119
critical
9.3
2008-03-24 CVE-2008-1471 Resource Management Errors vulnerability in Panda products
The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-bounds write of kernel memory.
local
low complexity
microsoft panda CWE-399
7.2
2008-02-12 CVE-2007-0065 Code Injection vulnerability in Microsoft Office and Visual Basic
Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.
network
low complexity
microsoft CWE-94
critical
10.0
2008-02-12 CVE-2008-0088 Improper Input Validation vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.
network
low complexity
microsoft CWE-20
6.8
2008-01-08 CVE-2007-5352 Permissions, Privileges, and Access Controls vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.
local
low complexity
microsoft CWE-264
7.2
2008-01-08 CVE-2007-0066 Unspecified vulnerability in Microsoft products
The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."
network
microsoft
7.1
2007-12-12 CVE-2007-3901 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Directx
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted SAMI file.
network
microsoft CWE-119
8.5
2007-12-12 CVE-2007-3895 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Directx
Buffer overflow in Microsoft DirectShow in Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted (1) WAV or (2) AVI file.
network
microsoft CWE-119
critical
9.3
2007-12-12 CVE-2007-3039 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Message Queuing
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103.
network
low complexity
microsoft CWE-119
critical
9.0