← Back

Microsoft

microsoft

14,951 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Jul 14, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argu...Show more
An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability.Show less
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Jul 13, 2000
N/A· v4
N/A· v3
2.6 LOW· v2
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.
1Microsoft
1Sql Server
Apr 16, 2026
Jul 11, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability.
1Microsoft
1Sql Server
Apr 16, 2026
Jul 7, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the "Stored Procedure Permissions" vulnerability.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jul 1, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
A Windows NT administrator account has the default name of Administrator.
1Microsoft
1Windows 2000
Apr 16, 2026
Jun 30, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash.
1Microsoft
1Windows 2000
Apr 16, 2026
Jun 30, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization.
1Microsoft
2Windows 95
Windows 98
Apr 16, 2026
Jun 29, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table.
1Microsoft
2Excel
Powerpoint
Apr 16, 2026
Jun 27, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the...Show more
Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Jun 27, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary comman...Show more
Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jun 15, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Windows 2000 allows a local user process to access another user's desktop within the same windows station, aka the "Desktop Separation" vulnerability.
1Microsoft
1Windows Nt
Apr 16, 2026
Jun 8, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authenticatio...Show more
The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Jun 6, 2000
N/A· v4
N/A· v3
2.6 LOW· v2
The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jun 5, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.
1Microsoft
2Exchange Server
Outlook
Apr 16, 2026
Jun 5, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.
1Microsoft
2Ie
Internet Explorer
Apr 16, 2026
Jun 5, 2000
N/A· v4
N/A· v3
2.6 LOW· v2
Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certi...Show more
Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities.Show less
1Microsoft
2Ie
Internet Explorer
Apr 16, 2026
Jun 5, 2000
N/A· v4
N/A· v3
2.6 LOW· v2
Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabiliti...Show more
Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
Jun 1, 2000
N/A· v4
N/A· v3
3.6 LOW· v2
The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key L...Show more
The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability.Show less
3Apple
LinuxMicrosoft
6Linux Kernel
MacosWindows 2000+3 more
Apr 16, 2026
Jun 1, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
A system does not present an appropriate legal message or warning to a user who is accessing it.
1Microsoft
1Windows Media Services
Apr 16, 2026
May 30, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder Request" vulnerability.