Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability. |
1Microsoft 3Frontpage Personal Web ServerWindows NtApr 16, 2026 Apr 19, 2000 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Component...Show more |
Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascr...Show more |
1Microsoft 5Windows 2000 Windows 98Windows 98se+2 moreApr 16, 2026 Apr 14, 2000 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query,...Show more |
Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link View Server-Side Component" vulnerability. |
The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Apr 12, 2000 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability. |
After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password. |
The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories. |
Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability. |
Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL. |
1Microsoft 6Commercial Internet System Internet Information ServerInternet Information Services+3 moreApr 16, 2026 Mar 30, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC...Show more |
1Microsoft 3Terminal Server Windows 2000Windows NtApr 16, 2026 Mar 30, 2000 N/A· v4 N/A· v3 2.1 LOW· v2 Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request. |
1Microsoft 1Internet Information Server Apr 16, 2026 Mar 20, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the "Chunked Transfer Encoding Buffer Overflow Vulnerability." |
1Microsoft 1Windows Media Rights Manager Apr 16, 2026 Mar 17, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the "Malformed Media License Request" Vulnerability. |
When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the...Show more |
Microsoft SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0 allow remote attackers to gain privileges via a malformed Select statement in an SQL query. |
1Microsoft 3Clip Art GreetingsHome PublishingApr 16, 2026 Mar 6, 2000 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability. |
1Microsoft 3Windows 95 Windows 98Windows 98seApr 16, 2026 Mar 4, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability. |
The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking. |