← Back

Microsoft

microsoft

14,951 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Apr 22, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field valu...Show more
Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.Show less
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Apr 22, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Apr 22, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Apr 22, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked...Show more
Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."Show less
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Apr 22, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Apr 22, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object...Show more
Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.Show less
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Apr 22, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Apr 22, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Apr 22, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote...Show more
The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote attackers to cause a denial of service (crash) when the URL parser accesses a null pointer.Show less
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Apr 22, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with...Show more
Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.Show less
1Microsoft
3Windows 2000
Windows NtWindows Xp
Apr 16, 2026
Apr 4, 2002
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.
1Microsoft
1Windows 2000
Apr 16, 2026
Apr 4, 2002
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.
1Microsoft
1Internet Explorer
Apr 16, 2026
Mar 29, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vu...Show more
The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Mar 25, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Internet Explorer 5.5 on Windows 98 allows remote web pages to cause a denial of service (hang) via extremely long values for form fields such as INPUT and TEXTAREA, which can be automatically filled via Javasc...Show more
Microsoft Internet Explorer 5.5 on Windows 98 allows remote web pages to cause a denial of service (hang) via extremely long values for form fields such as INPUT and TEXTAREA, which can be automatically filled via Javascript.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Mar 25, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not relea...Show more
Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released.Show less
3Hp
MicrosoftSun
5Java Jre Jdk
JdkJre+2 more
Apr 16, 2026
Mar 19, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earl...Show more
Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of SDK or JDK, aka a variant of the "Virtual Machine Verifier" vulnerability.Show less
1Microsoft
4Windows 2000
Windows 98Windows 98se+1 more
Apr 16, 2026
Mar 15, 2002
N/A· v4
N/A· v3
7.6 HIGH· v2
Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been impr...Show more
Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.Show less
2Microsoft
Sun
4Jdk
JreSdk+1 more
Apr 16, 2026
Mar 15, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another serv...Show more
Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 through 6.1 and 4.79 and earlier, (2) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, and possibly other implementations that use vulnerable versions of SDK or JDK.Show less
1Microsoft
4Internet Explorer
Sql ServerWindows Xp+1 more
Apr 16, 2026
Mar 8, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
1Microsoft
1Sql Server
Apr 16, 2026
Mar 8, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection.