← Back

Windows 2000

windows_2000

Vendor: Microsoft • 515 CVEs

CVEs (515)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
3Terminal Server
Windows 2000Windows Nt
Apr 16, 2026
Mar 30, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request.
1Microsoft
1Windows 2000
Apr 16, 2026
Feb 15, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 20, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Dec 31, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions th...Show more
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.Show less
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Dec 1, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
1Microsoft
3Windows 2000
Windows 98Windows Nt
Apr 16, 2026
Nov 17, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.
2Microsoft
Sun
5Solaris
SunosWindows 2000+2 more
Apr 16, 2026
Aug 11, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jul 29, 1999
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jul 20, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
1Microsoft
4Windows 2000
Windows 95Windows 98+1 more
Apr 16, 2026
Jul 3, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jun 30, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jun 23, 1999
N/A· v4
N/A· v3
7.1 HIGH· v2
The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.
1Microsoft
3Internet Information Server
Windows 2000Windows Nt
Apr 16, 2026
Jun 16, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
May 27, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
May 20, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
May 17, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.
1Microsoft
5Excel
Windows 2000Windows 95+2 more
Apr 16, 2026
May 7, 1999
N/A· v4
N/A· v3
2.6 LOW· v2
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
1Microsoft
3Backoffice
Windows 2000Windows Nt
Apr 16, 2026
Feb 12, 1999
N/A· v4
N/A· v3
2.1 LOW· v2
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
1Microsoft
3Terminal Server
Windows 2000Windows Nt
Apr 16, 2026
Jan 5, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.
1Microsoft
6Office
OutlookProject+3 more
Apr 16, 2026
Jan 1, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.