← Back

Microsoft

microsoft

14,951 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Windows 2000
Apr 16, 2026
Apr 20, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability.
1Microsoft
3Frontpage
Personal Web ServerWindows Nt
Apr 16, 2026
Apr 19, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Component...Show more
Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Apr 18, 2000
N/A· v4
N/A· v3
2.6 LOW· v2
Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascr...Show more
Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.Show less
1Microsoft
5Windows 2000
Windows 98Windows 98se+2 more
Apr 16, 2026
Apr 14, 2000
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query,...Show more
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.Show less
1Microsoft
2Frontpage
Visual Interdev
Apr 16, 2026
Apr 14, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link View Server-Side Component" vulnerability.
1Microsoft
2Terminal Server
Windows Nt
Apr 16, 2026
Apr 12, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Apr 12, 2000
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.
1Microsoft
1Windows Nt
Apr 16, 2026
Apr 11, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.
1Microsoft
1Windows 2000
Apr 16, 2026
Apr 7, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories.
1Microsoft
1Excel
Apr 16, 2026
Apr 3, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.
1Microsoft
1Index Server
Apr 16, 2026
Mar 31, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.
1Microsoft
6Commercial Internet System
Internet Information ServerInternet Information Services+3 more
Apr 16, 2026
Mar 30, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC...Show more
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.Show less
1Microsoft
3Terminal Server
Windows 2000Windows Nt
Apr 16, 2026
Mar 30, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request.
1Microsoft
1Internet Information Server
Apr 16, 2026
Mar 20, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the "Chunked Transfer Encoding Buffer Overflow Vulnerability."
1Microsoft
1Windows Media Rights Manager
Apr 16, 2026
Mar 17, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the "Malformed Media License Request" Vulnerability.
1Microsoft
1Sql Server
Apr 16, 2026
Mar 14, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the...Show more
When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password.Show less
1Microsoft
2Data Engine
Sql Server
Apr 16, 2026
Mar 8, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Microsoft SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0 allow remote attackers to gain privileges via a malformed Select statement in an SQL query.
1Microsoft
3Clip Art
GreetingsHome Publishing
Apr 16, 2026
Mar 6, 2000
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability.
1Microsoft
3Windows 95
Windows 98Windows 98se
Apr 16, 2026
Mar 4, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability.
1Microsoft
1Internet Explorer
Apr 16, 2026
Mar 1, 2000
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking.