Microsoft
microsoft
14,958 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,958)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) r...Show more |
Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls createElement to create a...Show more |
Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to...Show more |
Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka lo...Show more |
1Microsoft 2Internet Explorer Windows 7Apr 23, 2026 Aug 14, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have...Show more |
2Apple Microsoft5Mac Os X Mac Os X ServerSafari+2 moreApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors. |
1Microsoft 5Biztalk Server Internet Security And Acceleration ServerOffice+2 moreApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 20...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Aug 12, 2009 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors relat...Show more |
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Server 2008+2 moreApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by repl...Show more |
1Microsoft 4Windows 2003 Server Windows Server 2008Windows Vista+1 moreApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2; or 5.2 or 6.1 on Windows XP SP3; allows remote attacke...Show more |
1Microsoft 2Windows 2000 Windows 2003 ServerApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS I...Show more |
1Microsoft 2Windows 2000 Windows 2003 ServerApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet...Show more |
1Microsoft 4Windows 2000 Windows Server 2003Windows Vista+1 moreApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel m...Show more |
1Microsoft 4Windows 2003 Server Windows Server 2008Windows Vista+1 moreApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 8.5 HIGH· v2 Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a den...Show more |
1Microsoft 4Windows 2003 Server Windows Server 2008Windows Vista+1 moreApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows rem...Show more |
1Microsoft 4Windows 2003 Server Windows Server 2008Windows Vista+1 moreApr 23, 2026 Aug 12, 2009 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a de...Show more |
1Microsoft 3.net Framework Windows Server 2008Windows VistaApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 2.6 LOW· v2 ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial o...Show more |
1Microsoft 3Isa Server OfficeOffice Web ComponentsApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote at...Show more |
1Microsoft 6Windows 2000 Windows ServerWindows Server 2003+3 moreApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to e...Show more |
1Microsoft 3Isa Server OfficeOffice Web ComponentsApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, In...Show more |