Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl...Show more |
Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page. |
1Microsoft 1Internet Information Services Apr 16, 2026 Jul 5, 2005 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Con...Show more |
Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary c...Show more |
1Microsoft 1Log Sink Class Activex Control Apr 16, 2026 Jul 5, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files. |
Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter. |
Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers. |
1Microsoft 7Windows 2000 Windows 2000 Terminal ServicesWindows 2003 Server+4 moreApr 16, 2026 Jun 14, 2005 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page. |
Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field. |
1Microsoft 7Windows 2000 Windows 2000 Terminal ServicesWindows 2003 Server+4 moreApr 16, 2026 Jun 14, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field. |
Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file. |
1Microsoft 4Windows 2000 Windows 2003 ServerWindows 98+1 moreApr 16, 2026 Jun 14, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that t...Show more |
1Microsoft 2Windows 2003 Server Windows XpApr 16, 2026 Jun 14, 2005 N/A· v4 N/A· v3 7.2 HIGH· v2 Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters. |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 Jun 14, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server M...Show more |
The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command. |
Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascri...Show more |
3Microsoft MitSun3Kerberos 5 SunosTelnet ClientApr 16, 2026 Jun 14, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command. |
1Microsoft 4Windows 2000 Windows 2003 ServerWindows Nt+1 moreApr 16, 2026 Jun 13, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-n...Show more |
1Microsoft 2Remote Desktop Connection Windows Terminal Services Using RdpApr 16, 2026 Jun 1, 2005 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and...Show more |
User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and height values. |