Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDET...Show more |
1Microsoft 4Windows 2000 Windows 2000 Terminal ServicesWindows Nt+1 moreApr 16, 2026 Apr 2, 2003 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which trigg...Show more |
1Microsoft 2Windows 2000 Windows 2000 Terminal ServicesApr 16, 2026 Mar 31, 2003 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to II...Show more |
Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS serv...Show more |
1Microsoft 7Windows 2000 Windows 2000 Terminal ServicesWindows 98+4 moreApr 16, 2026 Mar 24, 2003 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page...Show more |
Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious...Show more |
The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, ak...Show more |
Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation wit...Show more |
Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter. |
Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles...Show more |
1Microsoft 4Windows 2000 Windows 2000 Terminal ServicesWindows Nt+1 moreApr 16, 2026 Feb 7, 2003 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service co...Show more |
1Microsoft 1Content Management Server Apr 16, 2026 Feb 7, 2003 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter. |
4Freebsd LinuxMicrosoft+1 more5Freebsd Linux KernelNetbsd+2 moreApr 16, 2026 Jan 17, 2003 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as d...Show more |
1Microsoft 3Windows 2000 Windows NtWindows XpApr 16, 2026 Dec 31, 2002 N/A· v4 N/A· v3 3.6 LOW· v2 NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs. |
NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented usernames and passwords from network traffic. |
Active Directory in Windows 2000, when supporting Kerberos V authentication and GSSAPI, allows remote attackers to cause a denial of service (hang) via an LDAP client that sets the page length to zero during a large requ...Show more |
The "System Restore" directory and subdirectories, and possibly other subdirectories in the "System Volume Information" directory on Windows XP Professional, have insecure access control list (ACL) permissions, which all...Show more |
2Microsoft Opera Software2Internet Explorer Opera Web BrowserApr 16, 2026 Dec 31, 2002 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event...Show more |
Microsoft Windows XP with Fast User Switching (FUS) enabled does not remove the "show processes from all users" privilege when the user is removed from the administrator group, which allows that user to view processes of...Show more |
Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email. |