Microsoft
microsoft
15,156 CVEs • 1,060 products
Products (1,060)
Click to collapseToggle
Products (1,060)
Click to collapse
CVEs (15,156)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of...Show more |
Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag. |
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and d...Show more |
5C2net HpMicrosoft+2 more13Certificate Server Collabra ServerDirectory Server+10 moreApr 16, 2026 Jun 26, 1998 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Information from SSL-encrypted sessions via PKCS #1. |
1Microsoft 2Internet Information Server Windows NtApr 16, 2026 Jun 1, 1998 N/A· v4 N/A· v3 5.0 MEDIUM· v2 In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL. |
Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and f...Show more |
2Microsoft Netscape2Communicator Internet ExplorerApr 16, 2026 Apr 1, 1998 N/A· v4 N/A· v3 7.5 HIGH· v2 A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc. |
Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size. |
Bonk variation of teardrop IP fragmentation denial of service. |
2Microsoft Netscape5Enterprise Server Fasttrack ServerFrontpage+2 moreApr 16, 2026 Feb 6, 1998 N/A· v4 7.0 HIGH· v3 5.0 MEDIUM· v2 Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names. |
2Jgaa Microsoft3Warftpd Windows 95Windows NtApr 16, 2026 Feb 1, 1998 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in War FTP allows remote execution of commands. |
Buffer overflow in Internet Explorer 4.0(1). |
2Ibm Microsoft2Exchange Server Lotus Domino Mail ServerApr 16, 2026 Jan 1, 1998 N/A· v4 N/A· v3 7.5 HIGH· v2 Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. |
Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large number of SNMP pack...Show more |
4Caldera HpMicrosoft+1 more5Hp Ux OpenlinuxSunos+2 moreApr 16, 2026 Dec 16, 1997 N/A· v4 N/A· v3 5.0 MEDIUM· v2 A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2. |
4Hp MicrosoftNetbsd+1 more5Hp Ux NetbsdSunos+2 moreApr 16, 2026 Dec 16, 1997 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Teardrop IP denial of service. |
6Cisco GnuHp+3 more8Hp Ux InetIos+5 moreApr 16, 2026 Dec 1, 1997 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Land IP denial of service. |
1Microsoft 3Internet Explorer Outlook ExpressWindows ExplorerApr 16, 2026 Nov 1, 1997 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol. |
All records in a WINS database can be deleted through SNMP for a denial of service. |
1Microsoft 1Internet Information Server Apr 16, 2026 Sep 1, 1997 N/A· v4 N/A· v3 6.4 MEDIUM· v2 IIS newdsn.exe CGI script allows remote users to overwrite files. |