Vulnerabilities > Microsoft > Windows 2000 > Critical

DATE CVE VULNERABILITY TITLE RISK
2012-09-25 CVE-2012-3324 Path Traversal vulnerability in IBM DB2 and DB2 Connect
Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to modify, delete, or read arbitrary files via a pathname in the file field.
network
low complexity
ibm microsoft CWE-22
critical
9.0
2010-04-14 CVE-2010-0268 Unspecified vulnerability in Microsoft Windows 2000, Windows Media Player and Windows XP
Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."
network
microsoft
critical
9.3
2010-04-14 CVE-2010-0478 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Windows 2000
Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability."
network
microsoft CWE-119
critical
9.3
2010-03-31 CVE-2010-0491 Resource Management Errors vulnerability in Microsoft products
Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object Memory Corruption Vulnerability."
network
microsoft CWE-399
critical
9.3
2010-03-31 CVE-2010-0805 Code Injection vulnerability in Microsoft Internet Explorer, Windows 2000 and Windows XP
The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the CTDCCtl::SecurityCHeckDataURL function, aka "Memory Corruption Vulnerability."
network
microsoft CWE-94
critical
9.3
2010-02-10 CVE-2010-0016 Improper Input Validation vulnerability in Microsoft Windows 2000, Windows Server 2003 and Windows XP
The SMB client implementation in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate response fields, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted response, aka "SMB Client Pool Corruption Vulnerability."
network
microsoft CWE-20
critical
9.3
2010-02-10 CVE-2010-0028 Numeric Errors vulnerability in Microsoft Windows 2000, Windows Server 2003 and Windows XP
Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."
network
microsoft CWE-189
critical
9.3
2009-12-13 CVE-2009-4210 Code Injection vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted media content.
network
microsoft CWE-94
critical
9.3
2009-12-13 CVE-2009-4309 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file.
network
microsoft CWE-119
critical
9.3
2009-12-13 CVE-2009-4310 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by data in an AVI file.
network
microsoft windows CWE-119
critical
9.3