← Back

Microsoft

microsoft

14,951 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
2Ie
Internet Explorer
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
2.6 LOW· v2
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vu...Show more
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
2.6 LOW· v2
The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability.
1Microsoft
3Excel
PowerpointWord
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.
1Microsoft
1Outlook
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.
1Microsoft
1Outlook
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files.
1Microsoft
3Frontpage
Internet Information ServerInternet Information Services
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without qu...Show more
Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.Show less
1Microsoft
2Windows 95
Windows 98
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Pi...Show more
The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation...Show more
The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability.Show less
2Microsoft
Netscape
2Communicator
Virtual Machine
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstra...Show more
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.Show less
1Microsoft
1Frontpage
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS de...Show more
The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.Show less
1Microsoft
1Frontpage
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.
1Microsoft
4Windows 2000
Windows 95Windows 98+1 more
Apr 16, 2026
Aug 29, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request i...Show more
Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.Show less
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jul 27, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Serve...Show more
The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability.Show less
1Microsoft
1Excel
Apr 16, 2026
Jul 26, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jul 25, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explor...Show more
The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative Shell Path" vulnerability.Show less
1Microsoft
1Outlook Express
Apr 16, 2026
Jul 20, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.
1Microsoft
2Outlook
Outlook Express
Apr 16, 2026
Jul 20, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vu...Show more
Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.Show less
1Microsoft
2Outlook
Outlook Express
Apr 16, 2026
Jul 18, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Jul 17, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.
1Microsoft
1Internet Explorer
Apr 16, 2026
Jul 14, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).