National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

Search Parameters:
  • Contains Software Flaws (CVE)
  • CPE Product Version: cpe:/o:microsoft:windows_2000:-:sp1:~~advanced_server~~~
There are 323 matching records.
Displaying matches 241 through 260.
Vuln ID Summary CVSS Severity
CVE-2001-0351

Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.

Published: July 21, 2001; 12:00:00 AM -04:00
    V2: 2.1 LOW
CVE-2001-0502

Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users.

Published: July 21, 2001; 12:00:00 AM -04:00
    V2: 4.6 MEDIUM
CVE-2001-1302

The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function.

Published: July 18, 2001; 12:00:00 AM -04:00
    V2: 2.1 LOW
CVE-2001-1238

Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.

Published: July 16, 2001; 12:00:00 AM -04:00
    V2: 4.6 MEDIUM
CVE-2001-1244

Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.

Published: July 07, 2001; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-2001-0238

Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.

Published: July 02, 2001; 12:00:00 AM -04:00
    V2: 7.5 HIGH
CVE-2001-0237

Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.

Published: June 27, 2001; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-2001-0241

Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.

Published: June 27, 2001; 12:00:00 AM -04:00
    V2: 10.0 HIGH
CVE-2001-0373

The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.

Published: June 18, 2001; 12:00:00 AM -04:00
    V2: 2.1 LOW
CVE-2001-0261

Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.

Published: June 02, 2001; 12:00:00 AM -04:00
    V2: 2.1 LOW
CVE-2001-1347

Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due to an exception, and allow hijacking of resources such as named pipes.

Published: May 24, 2001; 12:00:00 AM -04:00
    V2: 4.6 MEDIUM
CVE-2001-0147

Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records.

Published: May 03, 2001; 12:00:00 AM -04:00
    V2: 10.0 HIGH
CVE-2001-0324

Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.

Published: May 03, 2001; 12:00:00 AM -04:00
    V2: 2.6 LOW
CVE-2001-0015

Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process.

Published: March 12, 2001; 12:00:00 AM -05:00
    V2: 7.2 HIGH
CVE-2001-0046

The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.

Published: February 16, 2001; 12:00:00 AM -05:00
    V2: 4.6 MEDIUM
CVE-2001-0003

Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.

Published: February 12, 2001; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-2001-0014

Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.

Published: February 12, 2001; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-2001-0048

The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.

Published: February 12, 2001; 12:00:00 AM -05:00
    V2: 7.2 HIGH
CVE-2000-1089

Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.

Published: January 09, 2001; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-2000-1111

Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input.

Published: January 09, 2001; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM