Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended...Show more |
Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document. |
Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "U...Show more |
Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, ak...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a special...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 2.1 LOW· v2 Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerabilit...Show more |
Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications suc...Show more |
Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in a titlebar for a script-initiated popup window, which could facilitate phishing attacks. |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows 98+3 moreApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so th...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows 98+3 moreApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 7.2 HIGH· v2 The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests. |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows 98+3 moreApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 7.2 HIGH· v2 Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application. |
1Microsoft 4Windows 2000 Windows 98Windows 98se+1 moreApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message. |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows 98+3 moreApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer ove...Show more |
Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Chann...Show more |
Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka...Show more |
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, w...Show more |
1Microsoft 8Ie Internet ExplorerWindows 2000+5 moreApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability." |
The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authe...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows NtApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause...Show more |
1Microsoft 2Sharepoint Portal Server Sharepoint Team ServicesApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-sit...Show more |