← Back

Windows 2000

windows_2000

Vendor: Microsoft • 515 CVEs

CVEs (515)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jun 18, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive informati...Show more
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jun 2, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.
1Microsoft
1Windows 2000
Apr 16, 2026
May 24, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due...Show more
Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due to an exception, and allow hijacking of resources such as named pipes.Show less
1Microsoft
2Windows 2000
Windows 98
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
2.6 LOW· v2
Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connec...Show more
Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records.
1Microsoft
1Windows 2000
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Feb 16, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuratio...Show more
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious p...Show more
The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.
1Microsoft
4Office
Windows 2000Windows Me+1 more
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials an...Show more
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Dec 31, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.
1Microsoft
1Windows 2000
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the...Show more
The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability.Show less
1Microsoft
3Systems Management Server
Windows 2000Windows Nt
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an...Show more
Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Dec 11, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vul...Show more
Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Nov 21, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account loc...Show more
Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Nov 14, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the "Still Image Service Privilege Escalation" vulnerability.
1Microsoft
1Windows 2000
Apr 16, 2026
Nov 14, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server,...Show more
The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability.Show less
1Microsoft
3Windows 2000
Windows 98Windows 98se
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDef...Show more
The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option for the first file that is listed in the folder.Show less