← Back

Microsoft

microsoft

14,951 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Dec 1, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
1Microsoft
1Windows Nt
Apr 16, 2026
Nov 30, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.
1Microsoft
1Ie
Apr 16, 2026
Nov 29, 1999
N/A· v4
N/A· v3
7.2 HIGH· v2
Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.
1Microsoft
2Windows 95
Windows 98
Apr 16, 2026
Nov 29, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.
1Microsoft
1Sql Server
Apr 16, 2026
Nov 19, 1999
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.
1Microsoft
1Windows Nt
Apr 16, 2026
Nov 18, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.
1Microsoft
3Windows 2000
Windows 98Windows Nt
Apr 16, 2026
Nov 17, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.
1Microsoft
1Internet Explorer
Apr 16, 2026
Nov 17, 1999
N/A· v4
N/A· v3
2.6 LOW· v2
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
1Microsoft
1Internet Explorer
Apr 16, 2026
Nov 14, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.
1Microsoft
2Windows 95
Windows 98
Apr 16, 2026
Nov 12, 1999
N/A· v4
N/A· v3
7.6 HIGH· v2
The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability.
1Microsoft
4Ie
Internet ExplorerOutlook+1 more
Apr 16, 2026
Nov 11, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.
1Microsoft
1Windows Nt
Apr 16, 2026
Nov 4, 1999
N/A· v4
N/A· v3
7.2 HIGH· v2
The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.
1Microsoft
1Windows Nt
Apr 16, 2026
Nov 4, 1999
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.
2Microsoft
Netscape
3Ie
Internet ExplorerNavigator
Apr 16, 2026
Nov 1, 1999
N/A· v4
N/A· v3
2.6 LOW· v2
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.
1Microsoft
2Internet Explorer
Word
Apr 16, 2026
Nov 1, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Als...Show more
Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Oct 31, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.
1Microsoft
1Windows Nt
Apr 16, 2026
Oct 26, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.
1Microsoft
1Virtual Machine
Apr 16, 2026
Oct 21, 1999
N/A· v4
N/A· v3
7.6 HIGH· v2
Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability.
1Microsoft
1Java Virtual Machine
Apr 16, 2026
Oct 21, 1999
N/A· v4
N/A· v3
9.3 HIGH· v2
The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.
1Microsoft
1Internet Explorer
Apr 16, 2026
Oct 1, 1999
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.