Vulnerabilities > Microsoft > Windows 2000

DATE CVE VULNERABILITY TITLE RISK
2004-08-06 CVE-2004-0213 Missing Authentication for Critical Function vulnerability in Microsoft Windows 2000
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.
local
low complexity
microsoft CWE-306
7.8
2004-08-06 CVE-2004-0212 Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.
network
low complexity
avaya microsoft
critical
10.0
2004-08-06 CVE-2004-0210 Classic Buffer Overflow vulnerability in Microsoft Interix, Windows 2000 and Windows NT
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
local
low complexity
microsoft CWE-120
7.8
2004-08-06 CVE-2004-0202 Remote Malformed Packet Denial Of Service vulnerability in Microsoft DirectX DirectPlay
IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
network
low complexity
microsoft
5.0
2004-08-06 CVE-2004-0201 Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
network
low complexity
avaya microsoft
critical
10.0
2004-07-27 CVE-2004-0726 Unspecified vulnerability in Microsoft Windows 2000
The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.
network
low complexity
microsoft
7.5
2004-06-01 CVE-2004-0124 Unspecified vulnerability in Microsoft products
The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."
network
high complexity
microsoft
2.6
2004-06-01 CVE-2004-0123 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
network
low complexity
microsoft CWE-119
7.5
2004-06-01 CVE-2004-0120 Denial of Service vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.
network
low complexity
microsoft
5.0
2004-06-01 CVE-2004-0119 NULL Pointer Dereference vulnerability in Microsoft Windows 2000, Windows Server 2003 and Windows XP
The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.
network
low complexity
microsoft CWE-476
7.5