Page 112 of 637 results (0.008 seconds)

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 1

Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace. • https://www.exploit-db.com/exploits/20907 http://razor.bindview.com/publish/advisories/adv_mstelnet.html http://www.ciac.org/ciac/bulletins/l-092.shtml http://www.securityfocus.com/bid/2838 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-031 https://exchange.xforce.ibmcloud.com/vulnerabilities/6666 •

CVSS: 2.1EPSS: 0%CPEs: 3EXPL: 0

The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function. • http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0107&L=ntbugtraq&F=P&S=&P=1911 http://www.securityfocus.com/bid/3063 https://exchange.xforce.ibmcloud.com/vulnerabilities/6876 •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager. • http://www.securityfocus.com/archive/1/197195 http://www.securityfocus.com/bid/3033 https://exchange.xforce.ibmcloud.com/vulnerabilities/6919 • CWE-178: Improper Handling of Case Sensitivity •

CVSS: 5.0EPSS: 1%CPEs: 29EXPL: 2

Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process. • https://www.exploit-db.com/exploits/20997 http://www.securityfocus.com/archive/1/195457 http://www.securityfocus.com/bid/2997 https://exchange.xforce.ibmcloud.com/vulnerabilities/6824 •

CVSS: 7.5EPSS: 1%CPEs: 6EXPL: 0

Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests. • http://www.ciac.org/ciac/bulletins/l-074.shtml https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-022 https://exchange.xforce.ibmcloud.com/vulnerabilities/6405 •