← Back

Windows 2000

windows_2000

Vendor: Microsoft • 515 CVEs

CVEs (515)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
4Exchange Server
Sql ServerWindows 2000+1 more
Apr 16, 2026
Sep 20, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service vi...Show more
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.Show less
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Aug 31, 2001
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.
1Microsoft
1Windows 2000
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activities such as mail relaying.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jul 27, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt and pressing the F7 and enter keys several times while the command is executing, possibly...Show more
Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt and pressing the F7 and enter keys several times while the command is executing, possibly related to an exception handling error in csrss.exe.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows lo...Show more
Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable nam...Show more
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable nam...Show more
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name,...Show more
Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.
1Microsoft
3Frontpage Server Extensions
Windows 2000Windows Nt
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests.
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 18, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring err...Show more
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 16, 2001
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users t...Show more
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.Show less
7Freebsd
HpLinux+4 more
9Freebsd
Hp UxLinux Kernel+6 more
Apr 16, 2026
Jul 7, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data,...Show more
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.Show less
1Microsoft
6Windows 2000
Windows 95Windows 98+3 more
Apr 16, 2026
Jul 2, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.
1Microsoft
1Windows 2000
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.
1Microsoft
1Windows 2000
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.