Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 3Exchange Server OutlookWindows MessagingApr 16, 2026 Feb 29, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read R...Show more |
The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerab...Show more |
1Microsoft 3Ie Internet ExplorerOutlookApr 16, 2026 Feb 21, 2000 N/A· v4 N/A· v3 7.6 HIGH· v2 The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft. |
1Microsoft 3Ie Internet ExplorerVisual StudioApr 16, 2026 Feb 18, 2000 N/A· v4 N/A· v3 5.1 MEDIUM· v2 The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability. |
Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands. |
1Microsoft 3Windows 95 Windows 98Windows NtApr 16, 2026 Feb 18, 2000 N/A· v4 N/A· v3 7.2 HIGH· v2 Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive. |
Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability. |
The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs. |
1Microsoft 1Internet Information Server Apr 16, 2026 Feb 15, 2000 N/A· v4 N/A· v3 2.1 LOW· v2 IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory. |
The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the origi...Show more |
1Microsoft 3Windows 95 Windows 98Windows NtApr 16, 2026 Feb 4, 2000 N/A· v4 N/A· v3 2.1 LOW· v2 Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file. |
The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File"...Show more |
Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program. |
1Microsoft 1Internet Information Server Apr 16, 2026 Feb 2, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. |
The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creation" vulnerability. |
Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client. |
Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 26, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack. |
Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist. |
The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability. |