Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2001-0712 | 0.00 | — | 0.06 | Oct 30, 2001 | The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text… | |||
| CVE-2001-0547 | 0.00 | — | 0.02 | Sep 20, 2001 | Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion). | |||
| CVE-2001-0628 | 0.00 | — | 0.02 | Aug 14, 2001 | Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user. | |||
| CVE-2001-1288 | 0.00 | — | 0.06 | Jul 27, 2001 | Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt and pressing the F7 and enter keys several times while the command is executing, possibly related to an exception handling error in csrss.exe. | |||
| CVE-2001-0346 | 0.00 | — | 0.06 | Jul 21, 2001 | Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them. | |||
| CVE-2001-0344 | 0.00 | — | 0.02 | Jul 21, 2001 | An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account. | |||
| CVE-2001-0349 | 0.00 | — | 0.02 | Jul 21, 2001 | Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of… | |||
| CVE-2001-0350 | 0.00 | — | 0.01 | Jul 21, 2001 | Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second… | |||
| CVE-2001-0351 | 0.00 | — | 0.02 | Jul 21, 2001 | Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service. | |||
| CVE-2001-0501 | 0.00 | — | 0.02 | Jul 21, 2001 | Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner. | |||
| CVE-2001-0502 | 0.00 | — | 0.02 | Jul 21, 2001 | Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users. | |||
| CVE-2001-1302 | 0.00 | — | 0.02 | Jul 18, 2001 | The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the… | |||
| CVE-2001-1244 | 0.00 | — | 0.22 | Jul 7, 2001 | Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that… | |||
| CVE-2001-0338 | 0.00 | — | 0.05 | Jun 27, 2001 | Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation vulnerability." | |||
| CVE-2001-0246 | 0.00 | — | 0.06 | Jun 27, 2001 | Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the… | |||
| CVE-2001-0240 | 0.00 | — | 0.01 | Jun 27, 2001 | Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro. | |||
| CVE-2001-0332 | 0.00 | — | 0.06 | Jun 27, 2001 | Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using… | |||
| CVE-2001-0337 | 0.00 | — | 0.05 | Jun 27, 2001 | The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests. | |||
| CVE-2001-0373 | 0.00 | — | 0.02 | Jun 18, 2001 | The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information. | |||
| CVE-2001-0261 | 0.00 | — | 0.02 | Jun 2, 2001 | Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files. | |||
| CVE-2001-0281 | 0.00 | — | 0.05 | May 3, 2001 | Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges. | |||
| CVE-2001-0016 | 0.00 | — | 0.02 | Mar 12, 2001 | NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access. | |||
| CVE-2001-0015 | 0.00 | — | 0.03 | Mar 12, 2001 | Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process. | |||
| CVE-2001-0047 | 0.00 | — | 0.06 | Feb 16, 2001 | The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities. | |||
| CVE-2001-0090 | 0.00 | — | 0.04 | Feb 16, 2001 | The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the "Browser Print Template" vulnerability. | |||
| CVE-2001-0046 | 0.00 | — | 0.05 | Feb 16, 2001 | The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities. | |||
| CVE-2001-0091 | 0.00 | — | 0.05 | Feb 16, 2001 | The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability. | |||
| CVE-2001-0005 | 0.00 | — | 0.02 | Feb 12, 2001 | Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands. | |||
| CVE-2001-0048 | 0.00 | — | 0.02 | Feb 12, 2001 | The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password"… | |||
| CVE-2000-1139 | 0.00 | — | 0.05 | Jan 9, 2001 | The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability. | |||
| CVE-2000-1104 | 0.00 | — | 0.06 | Jan 9, 2001 | Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The… | |||
| CVE-2000-1088 | 0.00 | — | 0.03 | Jan 9, 2001 | The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to… | |||
| CVE-2000-1087 | 0.00 | — | 0.03 | Jan 9, 2001 | The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to… | |||
| CVE-2000-1086 | 0.00 | — | 0.03 | Jan 9, 2001 | The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to… | |||
| CVE-2000-1084 | 0.00 | — | 0.03 | Jan 9, 2001 | The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a… | |||
| CVE-2000-1082 | 0.00 | — | 0.03 | Jan 9, 2001 | The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a… | |||
| CVE-2000-0933 | 0.00 | — | 0.02 | Dec 19, 2000 | The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability. | |||
| CVE-2000-1217 | 0.00 | — | 0.02 | Nov 21, 2000 | Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login… | |||
| CVE-2000-0777 | 0.00 | — | 0.01 | Oct 20, 2000 | The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability. | |||
| CVE-2000-0771 | 0.00 | — | 0.02 | Oct 20, 2000 | Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability. | |||
| CVE-2000-0767 | 0.00 | — | 0.04 | Oct 20, 2000 | The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability. | |||
| CVE-2000-0765 | 0.00 | — | 0.04 | Oct 20, 2000 | Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability. | |||
| CVE-2000-0756 | 0.00 | — | 0.05 | Oct 20, 2000 | Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service. | |||
| CVE-2000-0753 | 0.00 | — | 0.05 | Oct 20, 2000 | The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files. | |||
| CVE-2000-0563 | 0.00 | — | 0.03 | Oct 20, 2000 | The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model. | |||
| CVE-2000-0790 | 0.00 | — | 0.01 | Oct 20, 2000 | The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option… | |||
| CVE-2000-0637 | 0.00 | — | 0.02 | Jul 26, 2000 | Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability. | |||
| CVE-2000-0663 | 0.00 | — | 0.02 | Jul 25, 2000 | The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative… | |||
| CVE-2000-0654 | 0.00 | — | 0.01 | Jul 11, 2000 | Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability. | |||
| CVE-2000-0603 | 0.00 | — | 0.02 | Jul 7, 2000 | Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the "Stored Procedure Permissions" vulnerability. |
- CVE-2001-0712Oct 30, 2001risk 0.00cvss —epss 0.06
The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text…
- CVE-2001-0547Sep 20, 2001risk 0.00cvss —epss 0.02
Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).
- CVE-2001-0628Aug 14, 2001risk 0.00cvss —epss 0.02
Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.
- CVE-2001-1288Jul 27, 2001risk 0.00cvss —epss 0.06
Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt and pressing the F7 and enter keys several times while the command is executing, possibly related to an exception handling error in csrss.exe.
- CVE-2001-0346Jul 21, 2001risk 0.00cvss —epss 0.06
Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.
- CVE-2001-0344Jul 21, 2001risk 0.00cvss —epss 0.02
An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.
- CVE-2001-0349Jul 21, 2001risk 0.00cvss —epss 0.02
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of…
- CVE-2001-0350Jul 21, 2001risk 0.00cvss —epss 0.01
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second…
- CVE-2001-0351Jul 21, 2001risk 0.00cvss —epss 0.02
Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.
- CVE-2001-0501Jul 21, 2001risk 0.00cvss —epss 0.02
Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.
- CVE-2001-0502Jul 21, 2001risk 0.00cvss —epss 0.02
Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users.
- CVE-2001-1302Jul 18, 2001risk 0.00cvss —epss 0.02
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the…
- CVE-2001-1244Jul 7, 2001risk 0.00cvss —epss 0.22
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that…
- CVE-2001-0338Jun 27, 2001risk 0.00cvss —epss 0.05
Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation vulnerability."
- CVE-2001-0246Jun 27, 2001risk 0.00cvss —epss 0.06
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the…
- CVE-2001-0240Jun 27, 2001risk 0.00cvss —epss 0.01
Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.
- CVE-2001-0332Jun 27, 2001risk 0.00cvss —epss 0.06
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using…
- CVE-2001-0337Jun 27, 2001risk 0.00cvss —epss 0.05
The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.
- CVE-2001-0373Jun 18, 2001risk 0.00cvss —epss 0.02
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.
- CVE-2001-0261Jun 2, 2001risk 0.00cvss —epss 0.02
Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.
- CVE-2001-0281May 3, 2001risk 0.00cvss —epss 0.05
Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.
- CVE-2001-0016Mar 12, 2001risk 0.00cvss —epss 0.02
NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access.
- CVE-2001-0015Mar 12, 2001risk 0.00cvss —epss 0.03
Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process.
- CVE-2001-0047Feb 16, 2001risk 0.00cvss —epss 0.06
The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities.
- CVE-2001-0090Feb 16, 2001risk 0.00cvss —epss 0.04
The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the "Browser Print Template" vulnerability.
- CVE-2001-0046Feb 16, 2001risk 0.00cvss —epss 0.05
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.
- CVE-2001-0091Feb 16, 2001risk 0.00cvss —epss 0.05
The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.
- CVE-2001-0005Feb 12, 2001risk 0.00cvss —epss 0.02
Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.
- CVE-2001-0048Feb 12, 2001risk 0.00cvss —epss 0.02
The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password"…
- CVE-2000-1139Jan 9, 2001risk 0.00cvss —epss 0.05
The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.
- CVE-2000-1104Jan 9, 2001risk 0.00cvss —epss 0.06
Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The…
- CVE-2000-1088Jan 9, 2001risk 0.00cvss —epss 0.03
The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to…
- CVE-2000-1087Jan 9, 2001risk 0.00cvss —epss 0.03
The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to…
- CVE-2000-1086Jan 9, 2001risk 0.00cvss —epss 0.03
The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to…
- CVE-2000-1084Jan 9, 2001risk 0.00cvss —epss 0.03
The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a…
- CVE-2000-1082Jan 9, 2001risk 0.00cvss —epss 0.03
The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a…
- CVE-2000-0933Dec 19, 2000risk 0.00cvss —epss 0.02
The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability.
- CVE-2000-1217Nov 21, 2000risk 0.00cvss —epss 0.02
Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login…
- CVE-2000-0777Oct 20, 2000risk 0.00cvss —epss 0.01
The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability.
- CVE-2000-0771Oct 20, 2000risk 0.00cvss —epss 0.02
Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.
- CVE-2000-0767Oct 20, 2000risk 0.00cvss —epss 0.04
The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability.
- CVE-2000-0765Oct 20, 2000risk 0.00cvss —epss 0.04
Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.
- CVE-2000-0756Oct 20, 2000risk 0.00cvss —epss 0.05
Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.
- CVE-2000-0753Oct 20, 2000risk 0.00cvss —epss 0.05
The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files.
- CVE-2000-0563Oct 20, 2000risk 0.00cvss —epss 0.03
The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.
- CVE-2000-0790Oct 20, 2000risk 0.00cvss —epss 0.01
The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option…
- CVE-2000-0637Jul 26, 2000risk 0.00cvss —epss 0.02
Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability.
- CVE-2000-0663Jul 25, 2000risk 0.00cvss —epss 0.02
The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative…
- CVE-2000-0654Jul 11, 2000risk 0.00cvss —epss 0.01
Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability.
- CVE-2000-0603Jul 7, 2000risk 0.00cvss —epss 0.02
Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the "Stored Procedure Permissions" vulnerability.
Page 311 of 314