← Back

Microsoft

microsoft

14,951 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Sql Server
Apr 16, 2026
May 30, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability.
1Microsoft
1Sql Server
Apr 16, 2026
May 30, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" v...Show more
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.Show less
1Microsoft
5Terminal Server
Windows 2000Windows 95+2 more
Apr 16, 2026
May 25, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability.
1Microsoft
1Windows Nt
Apr 16, 2026
May 25, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the "HostAnnouncement Flo...Show more
The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the "HostAnnouncement Flooding" or "HostAnnouncement Frame" vulnerability.Show less
2Be
Microsoft
6Beos
Terminal ServerWindows 2000+3 more
Apr 16, 2026
May 19, 2000
N/A· v4
N/A· v3
7.8 HIGH· v2
Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fr...Show more
Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
May 17, 2000
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability.
1Microsoft
1Internet Explorer
Apr 16, 2026
May 17, 2000
N/A· v4
N/A· v3
7.6 HIGH· v2
Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability.
1Microsoft
1Windows Nt
Apr 16, 2026
May 16, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request.
1Microsoft
1Internet Explorer
Apr 16, 2026
May 13, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an em...Show more
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post.Show less
1Microsoft
2Outlook
Outlook Express
Apr 16, 2026
May 12, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
May 11, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Readi...Show more
ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
May 11, 2000
N/A· v4
N/A· v3
2.6 LOW· v2
Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability.
1Microsoft
1Windows 2000
Apr 16, 2026
May 11, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data.
1Microsoft
10Access
ExcelFrontpage+7 more
Apr 16, 2026
May 11, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerabi...Show more
The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.Show less
1Microsoft
1Windows 2000
Apr 16, 2026
May 11, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NTMail 5.x allows network users to bypass the NTMail proxy restrictions by redirecting their requests to NTMail's web configuration server.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
May 11, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
May 10, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulne...Show more
Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.Show less
1Microsoft
3Frontpage
Internet Information ServerInternet Information Services
Apr 16, 2026
May 6, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which gener...Show more
The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.Show less
1Microsoft
2Windows 95
Windows 98
Apr 16, 2026
May 2, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name.
1Microsoft
3Terminal Server
Windows 2000Windows Nt
Apr 16, 2026
Apr 20, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerab...Show more
Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.Show less