Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file. |
Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands. |
1Microsoft 1Msn Setup Bulletin Board Services Apr 16, 2026 Sep 24, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured. |
1Microsoft 2Commercial Internet System Internet Information ServerApr 16, 2026 Sep 23, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions. |
1Microsoft 4Terminal Server Windows 95Windows 98se+1 moreApr 16, 2026 Sep 20, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability. |
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager. |
Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account. |
The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration...Show more |
1Microsoft 3Commercial Internet System Site ServerSite Server CommerceApr 16, 2026 Sep 10, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user. |
Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability. |
The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect. |
Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands. |
The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. |
2Microsoft Qualcomm4Eudora FrontpageInternet Explorer+1 moreApr 16, 2026 Aug 27, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service...Show more |
Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observ...Show more |
Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking. |
Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive informati...Show more |
The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. |
The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability. |
1Microsoft 1Internet Information Server Apr 16, 2026 Aug 19, 1999 N/A· v4 N/A· v3 7.1 HIGH· v2 When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". |