Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument. |
2Microsoft Sun5Solaris SunosWindows 2000+2 moreApr 16, 2026 Aug 11, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes. |
1Microsoft 3Commercial Internet System Internet Information ServerSite ServerApr 16, 2026 Aug 11, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. |
1Microsoft 4Commercial Internet System Internet Information ServerSite Server+1 moreApr 16, 2026 Aug 11, 1999 N/A· v4 N/A· v3 2.6 LOW· v2 Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. |
Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service. |
Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled. |
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file. |
The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability. |
Denial of service in Windows NT messenger service through a long username. |
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request. |
1Microsoft 4Data Access Components Index ServerInternet Information Server+1 moreApr 16, 2026 Jul 19, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jul 7, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for norma...Show more |
1Microsoft 1Internet Information Server Apr 16, 2026 Jul 6, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character. |
A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them. |
1Microsoft 4Windows 2000 Windows 95Windows 98+1 moreApr 16, 2026 Jul 3, 1999 N/A· v4 N/A· v3 7.8 HIGH· v2 Denial of service in various Windows systems via malformed, fragmented IGMP packets. |
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header. |
Denial of service in RAS/PPTP on NT systems. |
Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to b...Show more |
Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang. |
The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input. |