Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account. |
1Microsoft 3Frontpage Server Extensions Windows 2000Windows NtApr 16, 2026 Jul 21, 2001 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll. |
An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that...Show more |
Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests. |
1Microsoft 2Internet Explorer Windows Script HostApr 16, 2026 Jul 21, 2001 N/A· v4 N/A· v3 7.5 HIGH· v2 Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary p...Show more |
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring err...Show more |
Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite. |
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users t...Show more |
7Freebsd HpLinux+4 more9Freebsd Hp UxLinux Kernel+6 moreApr 16, 2026 Jul 7, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data,...Show more |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jul 4, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a fil...Show more |
Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type. |
1Microsoft 6Windows 2000 Windows 95Windows 98+3 moreApr 16, 2026 Jul 2, 2001 N/A· v4 N/A· v3 7.5 HIGH· v2 Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests. |
Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "We...Show more |
Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server...Show more |
1Microsoft 1Internet Information Server Apr 16, 2026 Jun 27, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jun 27, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jun 27, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jun 27, 2001 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jun 27, 2001 N/A· v4 N/A· v3 7.5 HIGH· v2 Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice. |
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local fra...Show more |