← Back

Microsoft

microsoft

14,951 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
2Windows 2000
Windows Xp
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP ad...Show more
Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Address Translation (NAT).Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
2.6 LOW· v2
Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file.
1Microsoft
1Exchange Server
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Excha...Show more
Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."
1Microsoft
4Windows 98
Windows 98seWindows Me+1 more
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Universal Plug and Play (UPnP) in Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service (memory consumption or crash) via a malformed UPnP request.
1Microsoft
1Windows Media Player
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.
1Microsoft
1Outlook Express
Apr 16, 2026
Dec 3, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line.
1Microsoft
1Internet Explorer
Apr 16, 2026
Nov 26, 2001
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript.
1Microsoft
1Internet Explorer
Apr 16, 2026
Nov 26, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe t...Show more
Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download.Show less
1Microsoft
1Windows Xp
Apr 16, 2026
Nov 21, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in helpctr.exe program in Microsoft Help Center for Windows XP allows remote attackers to execute arbitrary code via a long hcp: URL.
1Microsoft
1Internet Explorer
Apr 16, 2026
Nov 20, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgent) information that indicates that the patch has been installed, which could allow remote malicious web sites to more ea...Show more
Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgent) information that indicates that the patch has been installed, which could allow remote malicious web sites to more easily identify and exploit vulnerable clients.Show less
1Microsoft
1Internet Information Services
Apr 16, 2026
Nov 20, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters.
1Microsoft
1Internet Explorer
Apr 16, 2026
Nov 14, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have...Show more
Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing Vulnerability variant" of CVE-2001-0664.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Nov 14, 2001
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability."
1Microsoft
2Excel
Powerpoint
Apr 16, 2026
Oct 30, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the documen...Show more
Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Oct 30, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MI...Show more
The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text (.txt), JPEG (.jpg), etc.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Oct 30, 2001
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbi...Show more
Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150.Show less
1Microsoft
1Exchange Server
Apr 16, 2026
Oct 30, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.
1Microsoft
1Ie
Apr 16, 2026
Oct 30, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations w...Show more
Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP Request Encoding vulnerability."Show less