Microsoft
microsoft
14,958 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,958)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1Internet Information Services Apr 23, 2026 Dec 29, 2009 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) character to determine the file extension, which allows remote attackers to bypass intended extension r...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 23, 2026 Dec 13, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 23, 2026 Dec 13, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Dav...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 23, 2026 Dec 13, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Pau...Show more |
2Microsoft Windows4Media Player Windows 2000Windows 2003 Server+1 moreApr 23, 2026 Dec 13, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed...Show more |
1Microsoft 4Windows 2000 Windows 2003 ServerWindows Media Player+1 moreApr 23, 2026 Dec 13, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value i...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 23, 2026 Dec 13, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted media cont...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Dec 9, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Exten...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 23, 2026 Dec 9, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 7+4 moreApr 23, 2026 Dec 9, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 7+4 moreApr 23, 2026 Dec 9, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, lead...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 7+4 moreApr 23, 2026 Dec 9, 2009 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to...Show more |
1Microsoft 2Windows Server 2003 Windows Server 2008Apr 23, 2026 Dec 9, 2009 N/A· v4 N/A· v3 9.0 HIGH· v2 Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitr...Show more |
1Microsoft 2Windows Server 2003 Windows Server 2008Apr 23, 2026 Dec 9, 2009 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, whi...Show more |
1Microsoft 7Office Converter Pack Office WordWindows 2000+4 moreApr 23, 2026 Dec 9, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to ex...Show more |
1Microsoft 2Windows Server 2008 Windows VistaApr 23, 2026 Dec 9, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows...Show more |
1Microsoft 3Office Project Project Portfolio ServerProject ServerApr 23, 2026 Dec 9, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Proje...Show more |
Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not properly initialized or (2) are deleted, which allows remote attackers to execute arbitrary code via vectors involving a ca...Show more |
The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilit...Show more |
The printing functionality in Microsoft Internet Explorer 8 allows remote attackers to discover a local pathname, and possibly a local username, by reading the dc:title element of a PDF document that was generated from a...Show more |