← Back

Microsoft

microsoft

14,951 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Outlook Express
Apr 16, 2026
Sep 12, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not ru...Show more
Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script.Show less
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Aug 31, 2001
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.
1Microsoft
1Windows Nt
Apr 16, 2026
Aug 31, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.
1Microsoft
1Word
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.
1Microsoft
1Outlook
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.
1Microsoft
1Windows 2000
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activities such as mail relaying.
1Microsoft
1Windows Nt
Apr 16, 2026
Aug 3, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode.
1Microsoft
2Windows 98
Windows 98se
Apr 16, 2026
Jul 30, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP request packets with random source IP and MAC addresses, as demonstrated by ARPNuke.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jul 27, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt and pressing the F7 and enter keys several times while the command is executing, possibly...Show more
Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt and pressing the F7 and enter keys several times while the command is executing, possibly related to an exception handling error in csrss.exe.Show less
1Microsoft
1Netmeeting
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft NetMeeting 3.01 with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service via a malformed string to the NetMeeting service port, aka a variant of the "NetMeeting Desktop Sharing"...Show more
Microsoft NetMeeting 3.01 with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service via a malformed string to the NetMeeting service port, aka a variant of the "NetMeeting Desktop Sharing" vulnerability.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows lo...Show more
Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users.Show less
1Microsoft
1Word
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.
1Microsoft
3Index Server
Indexing ServiceInternet Information Server
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administra...Show more
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable nam...Show more
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable nam...Show more
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name,...Show more
Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.