← Back

Microsoft

microsoft

14,951 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Internet Explorer
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local fra...Show more
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability.Show less
1Microsoft
2Index Server
Indexing Service
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highli...Show more
Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.Show less
1Microsoft
1Index Server
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.
1Microsoft
1Windows Media Player
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows Media Player 7 and earlier stores Internet shortcuts in a user's Temporary Files folder with a fixed filename instead of in the Internet Explorer cache, which causes the HTML in those shortcuts to run in the Loca...Show more
Windows Media Player 7 and earlier stores Internet shortcuts in a user's Temporary Files folder with a fixed filename instead of in the Internet Explorer cache, which causes the HTML in those shortcuts to run in the Local Computer Zone instead of the Internet Zone, which allows remote attackers to read certain files.Show less
1Microsoft
1Windows Media Player
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Ov...Show more
Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed in MS:MS00-090.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.
1Microsoft
1Word
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.
1Microsoft
1Windows 2000
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jun 18, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive informati...Show more
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.Show less
1Microsoft
2Outlook
Outlook Express
Apr 16, 2026
Jun 5, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than...Show more
Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.Show less
1Microsoft
3Internet Explorer
OutlookOutlook Express
Apr 16, 2026
Jun 2, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the br...Show more
MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jun 2, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.
1Microsoft
1Internet Information Services
Apr 16, 2026
Jun 2, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.
1Microsoft
1Internet Explorer
Apr 16, 2026
Jun 2, 2001
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the T...Show more
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Jun 2, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.
1Microsoft
1Windows Media Player
Apr 16, 2026
Jun 2, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.
1Microsoft
2Exchange Server
Internet Information Services
Apr 16, 2026
Jun 2, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
1Microsoft
1Windows 2000
Apr 16, 2026
May 24, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due...Show more
Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due to an exception, and allow hijacking of resources such as named pipes.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
May 11, 2001
N/A· v4
N/A· v3
2.6 LOW· v2
Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./".
1Microsoft
2Windows 2000
Windows 98
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
2.6 LOW· v2
Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connec...Show more
Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.Show less