Vulnerabilities > Microsoft > Windows 2000

DATE CVE VULNERABILITY TITLE RISK
2001-07-21 CVE-2001-0345 Sessions DoS vulnerability in Microsoft Windows 2000 Telnet
Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.
network
low complexity
microsoft
5.0
2001-07-21 CVE-2001-0341 Buffer Overflow vulnerability in Microsoft products
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.
network
low complexity
microsoft
7.5
2001-07-21 CVE-2001-0018 Unspecified vulnerability in Microsoft Windows 2000
Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests.
network
low complexity
microsoft
5.0
2001-07-18 CVE-2001-1302 Unspecified vulnerability in Microsoft Windows 2000
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function.
local
low complexity
microsoft
2.1
2001-07-16 CVE-2001-1238 Improper Handling of Case Sensitivity vulnerability in Microsoft Windows 2000
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.
local
low complexity
microsoft CWE-178
7.8
2001-07-07 CVE-2001-1244 Denial of Service vulnerability in Multiple Vendor Small TCP MSS
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.
network
low complexity
freebsd hp linux microsoft netbsd openbsd sun
5.0
2001-07-02 CVE-2001-0238 Unspecified vulnerability in Microsoft products
Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.
network
low complexity
microsoft
7.5
2001-06-27 CVE-2001-0241 Buffer Overflow vulnerability in Microsoft IIS 5.0 .printer ISAPI Extension
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.
network
low complexity
microsoft
critical
10.0
2001-06-27 CVE-2001-0237 Unspecified vulnerability in Microsoft Windows 2000
Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.
network
low complexity
microsoft
5.0
2001-06-18 CVE-2001-0373 Unspecified vulnerability in Microsoft Windows 2000 and Windows NT
The default configuration of the Dr.
local
low complexity
microsoft
2.1