← Back

Microsoft

microsoft

14,951 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
3Exchange Server
OutlookWindows Messaging
Apr 16, 2026
Feb 29, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read R...Show more
Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.Show less
1Microsoft
1Windows Media Services
Apr 16, 2026
Feb 23, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerab...Show more
The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerability.Show less
1Microsoft
3Ie
Internet ExplorerOutlook
Apr 16, 2026
Feb 21, 2000
N/A· v4
N/A· v3
7.6 HIGH· v2
The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.
1Microsoft
3Ie
Internet ExplorerVisual Studio
Apr 16, 2026
Feb 18, 2000
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.
1Microsoft
1Site Server
Apr 16, 2026
Feb 18, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands.
1Microsoft
3Windows 95
Windows 98Windows Nt
Apr 16, 2026
Feb 18, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.
1Microsoft
1Internet Explorer
Apr 16, 2026
Feb 16, 2000
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability.
1Microsoft
1Windows 2000
Apr 16, 2026
Feb 15, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs.
1Microsoft
1Internet Information Server
Apr 16, 2026
Feb 15, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.
1Microsoft
1Windows Nt
Apr 16, 2026
Feb 14, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the origi...Show more
The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.Show less
1Microsoft
3Windows 95
Windows 98Windows Nt
Apr 16, 2026
Feb 4, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.
1Microsoft
1Windows Nt
Apr 16, 2026
Feb 4, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File"...Show more
The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.Show less
1Microsoft
1Frontpage
Apr 16, 2026
Feb 3, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program.
1Microsoft
1Internet Information Server
Apr 16, 2026
Feb 2, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.
1Microsoft
1Windows Nt
Apr 16, 2026
Feb 1, 2000
N/A· v4
N/A· v3
3.6 LOW· v2
The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creation" vulnerability.
1Microsoft
1Outlook Express
Apr 16, 2026
Feb 1, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client.
1Microsoft
1Virtual Machine
Apr 16, 2026
Jan 31, 2000
N/A· v4
N/A· v3
2.6 LOW· v2
Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.
1Microsoft
1Internet Information Server
Apr 16, 2026
Jan 26, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.
1Microsoft
1Index Server
Apr 16, 2026
Jan 26, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist.
1Microsoft
1Index Server
Apr 16, 2026
Jan 26, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability.