Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability. |
1Microsoft 3Windows 95 Windows 98Windows NtApr 16, 2026 Apr 12, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files. |
Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component. |
Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client. |
1Microsoft 2Frontpage Personal Web ServerApr 16, 2026 Mar 26, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack. |
Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directori...Show more |
The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the...Show more |
The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges. |
1Microsoft 3Windows 95 Windows 98Windows NtApr 16, 2026 Mar 8, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables. |
1Microsoft 2Frontpage Personal Web ServerApr 16, 2026 Mar 1, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL. |
Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting. |
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Feb 19, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. |
1Microsoft 3Backoffice Windows 2000Windows NtApr 16, 2026 Feb 12, 1999 N/A· v4 N/A· v3 2.1 LOW· v2 The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. |
1Microsoft 1Internet Information Server Apr 16, 2026 Feb 11, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. |
1Microsoft 1Internet Information Server Apr 16, 2026 Feb 9, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. |
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. |
Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) pac...Show more |
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. |
MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely. |