Microsoft
microsoft
14,958 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,958)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka...Show more |
Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Attribute Valid...Show more |
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Server 2003+2 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted app...Show more |
The kernel in Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows local users to gain privileges by creating a symbolic link from an untrusted registry hive to a trusted registry hive, aka "Windows Kernel Symbolic Link...Show more |
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Server 2003+2 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 7.2 HIGH· v2 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not properly allocate memory for the destination key associated with a symbolic-link registry key, which allows local users t...Show more |
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Server 2003+2 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (r...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows Server 2003+3 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which al...Show more |
1Microsoft 6Exchange Server Windows 2000Windows 2003 Server+3 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows...Show more |
1Microsoft 6Exchange Server Windows 2000Windows 2003 Server+3 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to c...Show more |
1Microsoft 3Virtual Pc Virtual ServerWindows Virtual PcApr 29, 2026 Apr 1, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restric...Show more |
1Microsoft 6Internet Explorer Windows 2003 ServerWindows Server 2003+3 moreApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Internet Explorer 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, leading to memory corruption, aka "HTML Rendering Memory Co...Show more |
1Microsoft 3Internet Explorer Windows 2000Windows XpApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that tri...Show more |
1Microsoft 8Internet Explorer Windows 2000Windows 2003 Server+5 moreApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML docume...Show more |
1Microsoft 7Internet Explorer Windows 2003 ServerWindows 7+4 moreApr 29, 2026 Mar 31, 2010 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup,...Show more |
1Microsoft 5Internet Explorer Windows 2000Windows 2003 Server+2 moreApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange eve...Show more |
1Microsoft 7Internet Explorer Windows 2003 ServerWindows 7+4 moreApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is de...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 2003 Server+4 moreApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Race Condition Memory Corruption...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 2003 Server+4 moreApr 29, 2026 Mar 31, 2010 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 2003 Server+4 moreApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is delet...Show more |
The Microsoft wireless keyboard uses XOR encryption with a key derived from the MAC address, which makes it easier for remote attackers to obtain keystroke information and inject arbitrary commands via a nearby wireless...Show more |