Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Windows 2000
Total 635 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-1593 1 Microsoft 3 Windows 2000, Windows 95, Windows 98 2026-06-16 7.6 HIGH N/A
Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server. NOTE: this problem may be limited when Windows 95/98 clients are used, or if the primary domain controller becomes unavailable.
CVE-1999-1358 1 Microsoft 2 Windows 2000, Windows Nt 2026-06-16 4.6 MEDIUM N/A
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.
CVE-1999-0918 1 Microsoft 4 Windows 2000, Windows 95, Windows 98 and 1 more 2026-06-16 7.8 HIGH N/A
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
CVE-1999-0875 2 Microsoft, Sun 5 Windows 2000, Windows 95, Windows 98se and 2 more 2026-06-16 7.5 HIGH N/A
DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
CVE-1999-0874 1 Microsoft 3 Internet Information Server, Windows 2000, Windows Nt 2026-06-16 10.0 HIGH N/A
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
CVE-1999-0819 1 Microsoft 2 Windows 2000, Windows Nt 2026-06-16 5.0 MEDIUM N/A
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
CVE-1999-0755 1 Microsoft 2 Windows 2000, Windows Nt 2026-06-16 5.0 MEDIUM N/A
Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.
CVE-1999-0726 1 Microsoft 2 Windows 2000, Windows Nt 2026-06-16 7.8 HIGH N/A
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
CVE-1999-0723 1 Microsoft 2 Windows 2000, Windows Nt 2026-06-16 7.1 HIGH N/A
The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.
CVE-1999-0721 1 Microsoft 2 Windows 2000, Windows Nt 2026-06-16 7.8 HIGH N/A
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
CVE-1999-0717 1 Microsoft 5 Excel, Windows 2000, Windows 95 and 2 more 2026-06-16 2.6 LOW N/A
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
CVE-1999-0716 1 Microsoft 2 Windows 2000, Windows Nt 2026-06-16 4.6 MEDIUM N/A
Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.
CVE-1999-0715 1 Microsoft 2 Windows 2000, Windows Nt 2026-06-16 4.6 MEDIUM N/A
Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.
CVE-1999-0700 1 Microsoft 2 Windows 2000, Windows Nt 2026-06-16 6.2 MEDIUM N/A
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
CVE-1999-0612 2 Gnu, Microsoft 4 Finger Service, Fingerd, Windows 2000 and 1 more 2026-06-16 N/A N/A
A version of finger is running that exposes valid user information to any entity on the network.
CVE-1999-0595 1 Microsoft 2 Windows 2000, Windows Nt 2026-06-16 2.1 LOW N/A
A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.
CVE-1999-0590 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, Windows 2000 and 3 more 2026-06-16 10.0 HIGH N/A
A system does not present an appropriate legal message or warning to a user who is accessing it.
CVE-1999-0585 1 Microsoft 2 Windows 2000, Windows Nt 2026-06-16 2.1 LOW N/A
A Windows NT administrator account has the default name of Administrator.
CVE-1999-0582 1 Microsoft 2 Windows 2000, Windows Nt 2026-06-16 5.0 MEDIUM N/A
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.
CVE-1999-0572 1 Microsoft 2 Windows 2000, Windows Nt 2026-06-16 9.3 HIGH N/A
.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.