Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Exchange Server Outlook Web AccessApr 23, 2026 Jul 8, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified HTML, a different vulnerability than CVE-20...Show more |
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified e-mail fields, a different vulnerability th...Show more |
1Microsoft 4Windows 2000 Windows Server 2003Windows Server 2008+1 moreApr 23, 2026 Jul 8, 2008 N/A· v4 N/A· v3 9.4 HIGH· v2 Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting "records from a...Show more |
Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted saved-search (.search-ms) files that are not properly handled when savin...Show more |
1Microsoft 6Data Engine Sql ServerSql Server Desktop Engine+3 moreApr 23, 2026 Jul 8, 2008 N/A· v4 N/A· v3 9.0 HIGH· v2 Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Inter...Show more |
1Microsoft 4Data Engine Sql ServerSql Server Desktop Engine+1 moreApr 23, 2026 Jul 8, 2008 N/A· v4 N/A· v3 9.0 HIGH· v2 Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement. |
1Microsoft 4Data Engine Sql ServerSql Server Desktop Engine+1 moreApr 23, 2026 Jul 8, 2008 N/A· v4 N/A· v3 9.0 HIGH· v2 Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL...Show more |
1Microsoft 5Data Engine Sql ServerSql Server Desktop Engine+2 moreApr 23, 2026 Jul 8, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon)...Show more |
1Microsoft 17Access ExcelFrontpage+14 moreApr 23, 2026 Jul 7, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S...Show more |
1Microsoft 1Office Snapshot Viewer Activex Apr 23, 2026 Jul 7, 2008 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitr...Show more |
2Fswiki Microsoft2Freestyle Wiki Internet ExplorerApr 23, 2026 Jul 7, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.6.2 and earlier, and 3.6.3 dev3 and earlier development versions, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTM...Show more |
1Microsoft 1Visual Basic Enterprise Edition Apr 23, 2026 Jul 2, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 Buffer overflow in a certain ActiveX control (vb6skit.dll) in Microsoft Visual Basic Enterprise Edition 6.0 SP6 might allow remote attackers to execute arbitrary code via a long lpstrLinkPath argument to the fCreateShell...Show more |
Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String data type, and use a frame from a different domain to observe domain-ind...Show more |
Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change the location property of a frame via the Object data type, and use a frame from a different domain to observe domain-ind...Show more |
Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1...Show more |
2Microsoft Xchat2Internet Explorer XchatApr 23, 2026 Jun 24, 2008 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI. |
Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly...Show more |
1Microsoft 3Windows Nt Windows VistaWindows XpApr 23, 2026 Jun 12, 2008 N/A· v4 N/A· v3 8.3 HIGH· v2 The Bluetooth stack in Microsoft Windows XP SP2 and SP3, and Vista Gold and SP1, allows physically proximate attackers to execute arbitrary code via a large series of Service Discovery Protocol (SDP) packets. |
1Microsoft 2Windows 2000 Windows 2003 ServerApr 23, 2026 Jun 12, 2008 N/A· v4 N/A· v3 7.2 HIGH· v2 The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memo...Show more |
1Microsoft 3Windows 2003 Server Windows NtWindows XpApr 23, 2026 Jun 12, 2008 N/A· v4 N/A· v3 7.1 HIGH· v2 Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a cr...Show more |