Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversi...Show more |
Microsoft Windows 2000 SP4 does not properly validate an RPC server during mutual authentication over SSL, which allows remote attackers to spoof an RPC server, aka the "RPC Mutual Authentication Vulnerability." |
1Microsoft 4Windows 2000 Windows 2003 ServerWindows Nt+1 moreApr 16, 2026 Jun 13, 2006 N/A· v4 N/A· v3 9.3 HIGH· v2 Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source rout...Show more |
1Microsoft 4Ie Internet ExplorerWindows 2003 Server+1 moreApr 16, 2026 Jun 13, 2006 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted A...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 Jun 13, 2006 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseF...Show more |
1Microsoft 3Windows 2000 Windows Server 2003Windows XpApr 16, 2026 Jun 13, 2006 N/A· v4 N/A· v3 10.0 HIGH· v2 The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 Jun 13, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 Jun 13, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows 98+3 moreApr 16, 2026 Jun 13, 2006 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote...Show more |
Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX control...Show more |
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown...Show more |
Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size. |
Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a...Show more |
1Microsoft 3Windows 98 Windows 98seWindows MeApr 16, 2026 Jun 13, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the PolyPolygon function in Graphics Rendering Engine on Microsoft Windows 98 and Me allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) or EMF image with a sum of entries i...Show more |
Unspecified vulnerability in Microsoft NetMeeting 3.01 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via crafted inputs that trigger memory corruption...Show more |
2Canon Microsoft2Ie Network Camera Server Vb101Apr 16, 2026 Jun 7, 2006 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Internet Explorer 6 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javasc...Show more |
Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of se...Show more |
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object point...Show more |
The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attac...Show more |
1Microsoft 1Infotech Storage System Library Apr 16, 2026 May 10, 2006 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Heap-based buffer overflow in Microsoft Infotech Storage System Library (itss.dll) allows user-assisted attackers to execute arbitrary code via a crafted CHM / ITS file that triggers the overflow while decompiling. |