Vulnerabilities > Microsoft > Windows 2000 > Medium

DATE CVE VULNERABILITY TITLE RISK
1999-12-31 CVE-1999-1358 Unspecified vulnerability in Microsoft Windows 2000 and Windows NT
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.
local
low complexity
microsoft
4.6
1999-12-01 CVE-1999-0819 Unspecified vulnerability in Microsoft Windows 2000 and Windows NT
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
network
low complexity
microsoft
5.0
1999-01-01 CVE-1999-0384 Unspecified vulnerability in Microsoft products
The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.
local
low complexity
microsoft
4.6
1997-07-01 CVE-1999-0153 Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
network
low complexity
microsoft sco
5.0
1997-01-01 CVE-1999-0582 Unspecified vulnerability in Microsoft Windows 2000 and Windows NT
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g.
network
low complexity
microsoft
5.0
1997-01-01 CVE-1999-0534 Unspecified vulnerability in Microsoft Windows 2000 and Windows NT
A Windows NT user has inappropriate rights or privileges, e.g.
local
low complexity
microsoft
4.6