Vulnerabilities > Microsoft > Windows 2000

DATE CVE VULNERABILITY TITLE RISK
2007-04-04 CVE-2007-1211 Resource Management Errors vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-assisted remote attackers to cause a denial of service (possibly persistent restart) via a crafted Windows Metafile (WMF) image that causes an invalid dereference of an offset in a kernel structure, a related issue to CVE-2005-4560.
network
microsoft CWE-399
7.1
2007-04-04 CVE-2006-5586 Local Privilege Escalation vulnerability in Microsoft Windows 2000 and Windows XP
The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability."
local
low complexity
microsoft
7.2
2007-03-30 CVE-2007-0038 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7.
network
microsoft CWE-119
critical
9.3
2007-03-30 CVE-2007-1765 Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7.
network
microsoft avaya
critical
9.3
2007-03-28 CVE-2007-1727 Remote Unauthorized Access vulnerability in HP OpenView Network Node Manager
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.
network
low complexity
hp linux microsoft sun
6.5
2007-03-26 CVE-2007-1692 Configuration vulnerability in Microsoft Windows 2000 and Windows 2003 Server
The default configuration of Microsoft Windows uses the Web Proxy Autodiscovery Protocol (WPAD) without static WPAD entries, which might allow remote attackers to intercept web traffic by registering a proxy server using WINS or DNS, then responding to WPAD requests, as demonstrated using Internet Explorer.
network
low complexity
microsoft CWE-16
7.5
2007-03-24 CVE-2007-1645 Remote Security vulnerability in TFTP Server 2000
Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69.
network
low complexity
microsoft futuresoft
critical
10.0
2007-03-20 CVE-2007-1512 Denial-Of-Service vulnerability in Visual Studio .NET Professional Edition
Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to have an unknown impact (probably crash) via an RTF file with a malformed OLE object, which results in writing two 0x00 characters past the end of szBuffer, aka the "MFC42u.dll Off-by-Two Overflow." NOTE: this issue is due to an incomplete patch (MS07-012) for CVE-2007-0025.
network
low complexity
microsoft
critical
10.0
2007-03-08 CVE-2007-1347 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Windows Explorer
Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.
network
microsoft CWE-119
7.1
2007-02-23 CVE-2006-7039 Remote Denial Of Service vulnerability in Atrium Software Mercur Messaging 2005 5.0Sp3
The IMAP4 service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (crash) via a message with a long subject field.
network
low complexity
microsoft atrium-software
5.0