Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fms Inc. Microsoft2Access Total Vb SourcebookApr 16, 2026 Jan 1, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data. |
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection. |
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service. |
2Microsoft Netscape2Internet Explorer NavigatorApr 16, 2026 Dec 1, 1998 N/A· v4 N/A· v3 2.6 LOW· v2 Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing. |
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. |
Buffer overflow in NetMeeting allows denial of service and remote command execution. |
2Broadcom Microsoft3Arcserve Backup Exchange ServerInoculanApr 16, 2026 Nov 12, 1998 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext. |
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence...Show more |
Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste. |
The Windows NT guest account is enabled. |
A Windows NT domain user or administrator account has a default, null, blank, or missing password. |
A Windows NT domain user or administrator account has a guessable password. |
The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka S...Show more |
Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability. |
NT users can gain debug-level access on a system process using the Sechole exploit. |
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of...Show more |
Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag. |
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and d...Show more |
5C2net HpMicrosoft+2 more13Certificate Server Collabra ServerDirectory Server+10 moreApr 16, 2026 Jun 26, 1998 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Information from SSL-encrypted sessions via PKCS #1. |
1Microsoft 2Internet Information Server Windows NtApr 16, 2026 Jun 1, 1998 N/A· v4 N/A· v3 5.0 MEDIUM· v2 In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL. |