Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM obj...Show more |
Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy...Show more |
Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard...Show more |
The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow via steps in which a terminating thread causes Asynchronous Procedure...Show more |
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which...Show more |
Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cas...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 Dec 4, 2005 N/A· v4 N/A· v3 4.9 MEDIUM· v2 NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that h...Show more |
1Microsoft 2Windows 2000 Windows 2003 ServerApr 16, 2026 Dec 1, 2005 N/A· v4 N/A· v3 7.8 HIGH· v2 The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consum...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 Nov 29, 2005 N/A· v4 N/A· v3 7.6 HIGH· v2 Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 Nov 29, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enh...Show more |
Unquoted Windows search path vulnerability in Microsoft Antispyware 1.0.509 (Beta 1) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, involving the programs (1) GIANTAntiSpy...Show more |
PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC...Show more |
By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer. |
The HTML rendering engine in Microsoft Internet Explorer 6.0 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML in corrupted images and other files such as .GIF, JPG, and WAV, which is rendere...Show more |
1Microsoft 4Ie Windows 2000Windows 2003 Server+1 moreApr 16, 2026 Oct 21, 2005 N/A· v4 N/A· v3 2.6 LOW· v2 The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted,...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 Oct 21, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in t...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 Oct 21, 2005 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to...Show more |
1Microsoft 4Windows 2000 Windows 2003 ServerWindows Explorer+1 moreApr 16, 2026 Oct 21, 2005 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbit...Show more |
Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number...Show more |
1Microsoft 4Exchange Server Windows 2000Windows Server 2003+1 moreApr 16, 2026 Oct 13, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a l...Show more |