← Back

Windows 98

windows_98

Vendor: Microsoft • 87 CVEs

CVEs (87)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
2Windows 95
Windows 98
Apr 16, 2026
Aug 16, 1999
N/A· v4
N/A· v3
2.6 LOW· v2
Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.
1Microsoft
4Windows 2000
Windows 95Windows 98+1 more
Apr 16, 2026
Jul 3, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
1Microsoft
5Excel
Windows 2000Windows 95+2 more
Apr 16, 2026
May 7, 1999
N/A· v4
N/A· v3
2.6 LOW· v2
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
1Microsoft
3Windows 95
Windows 98Windows Nt
Apr 16, 2026
Apr 12, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.
1Microsoft
3Windows 95
Windows 98Windows Nt
Apr 16, 2026
Mar 8, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.
1Microsoft
2Windows 95
Windows 98
Apr 16, 2026
Feb 6, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) pac...Show more
Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing.Show less
1Microsoft
1Windows 98
Apr 16, 2026
Jan 25, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.