← Back

Microsoft

microsoft

14,951 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fms Inc.
Microsoft
2Access
Total Vb Sourcebook
Apr 16, 2026
Jan 1, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
1Microsoft
1Windows Nt
Apr 16, 2026
Jan 1, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
1Microsoft
1Windows Nt
Apr 16, 2026
Jan 1, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
2Microsoft
Netscape
2Internet Explorer
Navigator
Apr 16, 2026
Dec 1, 1998
N/A· v4
N/A· v3
2.6 LOW· v2
Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.
1Microsoft
1Exchange Server
Apr 16, 2026
Dec 1, 1998
N/A· v4
N/A· v3
10.0 HIGH· v2
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.
1Microsoft
1Netmeeting
Apr 16, 2026
Dec 1, 1998
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in NetMeeting allows denial of service and remote command execution.
2Broadcom
Microsoft
3Arcserve Backup
Exchange ServerInoculan
Apr 16, 2026
Nov 12, 1998
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.
1Microsoft
2Windows 95
Windows Nt
Apr 16, 2026
Oct 5, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence...Show more
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Oct 1, 1998
N/A· v4
N/A· v3
2.6 LOW· v2
Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.
1Microsoft
1Windows Nt
Apr 16, 2026
Oct 1, 1998
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Windows NT guest account is enabled.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Oct 1, 1998
N/A· v4
N/A· v3
7.2 HIGH· v2
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Oct 1, 1998
N/A· v4
N/A· v3
7.2 HIGH· v2
A Windows NT domain user or administrator account has a guessable password.
1Microsoft
1Windows Nt
Apr 16, 2026
Sep 29, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka S...Show more
The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Sep 4, 1998
N/A· v4
N/A· v3
2.6 LOW· v2
Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.
1Microsoft
1Windows Nt
Apr 16, 2026
Aug 1, 1998
N/A· v4
N/A· v3
7.2 HIGH· v2
NT users can gain debug-level access on a system process using the Sechole exploit.
1Microsoft
1Windows Nt
Apr 16, 2026
Aug 1, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of...Show more
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Jul 28, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.
1Microsoft
1Sql Server
Apr 16, 2026
Jun 29, 1998
N/A· v4
N/A· v3
7.2 HIGH· v2
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and d...Show more
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.Show less
5C2net
HpMicrosoft+2 more
13Certificate Server
Collabra ServerDirectory Server+10 more
Apr 16, 2026
Jun 26, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Information from SSL-encrypted sessions via PKCS #1.
1Microsoft
2Internet Information Server
Windows Nt
Apr 16, 2026
Jun 1, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.