Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 27, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 27, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jan 26, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 26, 1999 N/A· v4 N/A· v3 7.8 HIGH· v2 The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts. |
Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 24, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command. |
Windows NT 4.0 beta allows users to read and delete shares. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 14, 1999 N/A· v4 N/A· v3 2.1 LOW· v2 When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information...Show more |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 14, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands. |
1Microsoft 3Terminal Server Windows 2000Windows NtApr 16, 2026 Jan 5, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. |
The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. |
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. |
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. |
A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. |
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. |
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. |
A system-critical Windows NT file or directory has inappropriate permissions. |
Windows NT automatically logs in an administrator upon rebooting. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 1, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. |
1Microsoft 6Office OutlookProject+3 moreApr 16, 2026 Jan 1, 1999 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content. |