← Back

Microsoft

microsoft

14,951 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Sql Server
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.
1Microsoft
3Frontpage Server Extensions
Windows 2000Windows Nt
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.
1Microsoft
1Exchange Server
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that...Show more
An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests.
1Microsoft
2Internet Explorer
Windows Script Host
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary p...Show more
Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 18, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring err...Show more
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function.Show less
1Microsoft
1Exchange Server
Apr 16, 2026
Jul 16, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.
1Microsoft
1Windows 2000
Apr 16, 2026
Jul 16, 2001
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users t...Show more
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.Show less
7Freebsd
HpLinux+4 more
9Freebsd
Hp UxLinux Kernel+6 more
Apr 16, 2026
Jul 7, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data,...Show more
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.Show less
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Jul 4, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a fil...Show more
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.Show less
1Microsoft
1Isa Server
Apr 16, 2026
Jul 2, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.
1Microsoft
6Windows 2000
Windows 95Windows 98+3 more
Apr 16, 2026
Jul 2, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.
1Microsoft
1Internet Explorer
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "We...Show more
Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server...Show more
Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation vulnerability."Show less
1Microsoft
1Internet Information Server
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.
1Microsoft
1Internet Information Server
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.
1Microsoft
1Internet Information Server
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters.
1Microsoft
1Internet Information Server
Apr 16, 2026
Jun 27, 2001
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.
1Microsoft
1Internet Information Server
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.
1Microsoft
1Internet Explorer
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local fra...Show more
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.Show less