Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaScript that calls IsCo...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows NtApr 16, 2026 Mar 3, 2006 N/A· v4 N/A· v3 7.8 HIGH· v2 The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information...Show more |
Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz. |
The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop...Show more |
Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitimate "href" attribute, a form whose action...Show more |
Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to s...Show more |
1Microsoft 7Windows 2000 Windows 2003 ServerWindows 98+4 moreApr 16, 2026 Feb 14, 2006 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote at...Show more |
Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Tem...Show more |
1Microsoft 2Windows 2003 Server Windows XpApr 16, 2026 Feb 14, 2006 N/A· v4 N/A· v3 7.8 HIGH· v2 Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability." |
1Microsoft 2Windows 2003 Server Windows XpApr 16, 2026 Feb 14, 2006 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a d...Show more |
1Microsoft 3Office Windows 2003 ServerWindows XpApr 16, 2026 Feb 14, 2006 N/A· v4 N/A· v3 7.2 HIGH· v2 The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "...Show more |
1Microsoft 7Windows 2000 Windows 2000 Advanced ServerWindows 2003 Server+4 moreApr 16, 2026 Feb 14, 2006 N/A· v4 N/A· v3 9.3 HIGH· v2 Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to ex...Show more |
Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configu...Show more |
jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, wh...Show more |
1Microsoft 2Html Help Html Help WorkshopApr 16, 2026 Feb 6, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via...Show more |
urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attrib...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 Feb 1, 2006 N/A· v4 N/A· v3 2.1 LOW· v2 The VDM (Virtual DOS Machine) emulation environment for MS-DOS applications in Windows 2000, Windows XP SP2, and Windows Server 2003 allows local users to read the first megabyte of memory and possibly obtain sensitive i...Show more |
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 Jan 22, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer...Show more |
The "Remember my Password" feature in MSN Messenger 7.5 stores passwords in an encrypted format under the HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Creds registry key, which might allow local users to obtain the o...Show more |