Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the...Show more |
1Microsoft 7Windows 2000 Windows 2003 ServerWindows 98+4 moreApr 16, 2026 Jan 10, 2006 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or we...Show more |
1Microsoft 3Exchange Server OfficeOutlookApr 16, 2026 Jan 10, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows 98+3 moreApr 16, 2026 Jan 10, 2006 N/A· v4 N/A· v3 9.3 HIGH· v2 An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows 98+3 moreApr 16, 2026 Jan 9, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with argumen...Show more |
The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use with...Show more |
The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use withi...Show more |
The System Monitor Source Properties control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended...Show more |
The Outlook Progress Ctl control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use wit...Show more |
1Microsoft 1Outlook Express Book Control Apr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Outlook Express Address Book control, when using Internet Explorer 6, allows remote attackers to cause a denial of service (NULL dereference and browser crash) by creating the OutlookExpress.AddressBook COM object, w...Show more |
2Canon Microsoft3Ie Internet ExplorerNetwork Camera Server Vb101Apr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsof...Show more |
Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX). |
1Microsoft 6Ie Internet ExplorerWindows 2000+3 moreApr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain comb...Show more |
The Microsoft Wireless Zero Configuration system (WZCS) allows local users to access WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key via certain calls to the WZCQueryInterface API function in wzcsapi.d...Show more |
The Microsoft Wireless Zero Configuration system (WZCS) stores WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key in plaintext in memory of the explorer process, which allows attackers with access to proc...Show more |
Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to spoof the URL in the status bar via the title in an image in a link to a trusted site within a form to the malicious site. |
Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into performing a drag-and-drop action from certain objects, such as...Show more |
1Microsoft 2Windows 2003 Server Windows XpApr 16, 2026 Dec 28, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function...Show more |
1Microsoft 1Internet Information Services Apr 16, 2026 Dec 20, 2005 N/A· v4 N/A· v3 7.8 HIGH· v2 The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" thro...Show more |
1Microsoft 3Ie Windows 2003 ServerWindows XpApr 16, 2026 Dec 15, 2005 N/A· v4 N/A· v3 7.8 HIGH· v2 mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a...Show more |