1) It makes it easier for attackers to mount attacks. It gives them another tool they can use to attack your service. My guess is supporting SSLv2 makes it easier to mount downgrade attacks against a server (i.e. an attack where you can trick the client and the server to use SSLv2 instead of a secure protocol).
2) You should not run unnecessary code on your services. It gives attackers a chance to hack your service because the unnecessary code can be exploited.