Vulnerabilities > Microsoft > Windows 2003 Server > 2000

DATE CVE VULNERABILITY TITLE RISK
2007-03-26 CVE-2007-1692 Configuration vulnerability in Microsoft Windows 2000 and Windows 2003 Server
The default configuration of Microsoft Windows uses the Web Proxy Autodiscovery Protocol (WPAD) without static WPAD entries, which might allow remote attackers to intercept web traffic by registering a proxy server using WINS or DNS, then responding to WPAD requests, as demonstrated using Internet Explorer.
network
low complexity
microsoft CWE-16
7.5
2007-02-13 CVE-2007-0025 Code Injection vulnerability in Microsoft Visual Studio .Net and Windows 2003 Server
The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.
network
microsoft CWE-94
critical
9.3
2006-12-12 CVE-2006-5583 Remote Code Execution vulnerability in Microsoft Windows 2003 Server 2000/Sp1/Xpsp2
Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."
network
low complexity
microsoft
critical
10.0
2005-05-02 CVE-2005-0050 Improper Input Validation vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows NT
The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."
network
low complexity
microsoft CWE-20
critical
10.0
2005-01-27 CVE-2004-0892 Unspecified vulnerability in Microsoft ISA Server, Proxy Server and Windows 2003 Server
Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.
network
low complexity
microsoft
7.5
2005-01-10 CVE-2004-1080 Remote Memory Corruption vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows NT
The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."
network
low complexity
microsoft
critical
10.0