Microsoft
microsoft
15,156 CVEs • 1,060 products
Products (1,060)
Click to collapseToggle
Products (1,060)
Click to collapse
CVEs (15,156)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" opti...Show more |
11Apple CiscoHp+8 more14Aix BsdosHp Ux+11 moreMay 28, 2026 Aug 1, 1997 N/A· v4 4.0 MEDIUM· v3 2.1 LOW· v2 ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts. |
The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain direct...Show more |
Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorr...Show more |
2Microsoft Netscape2Communicator Internet ExplorerApr 16, 2026 Jul 8, 1997 N/A· v4 N/A· v3 2.6 LOW· v2 JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability. |
2Microsoft Sco4Openserver Windows 2000Windows 95+1 moreApr 16, 2026 Jul 1, 1997 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke. |
4Freebsd LinuxMicrosoft+1 more4Freebsd Linux KernelNetbsd+1 moreApr 16, 2026 Jul 1, 1997 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Listening TCP ports are sequentially allocated, allowing spoofing attacks. |
Denial of service in Windows NT DNS servers by flooding port 53 with too many characters. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jun 1, 1997 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Denial of service in IIS using long URLs. |
Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service. |
Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel...Show more |
Denial of service through Winpopup using large user names. |
Remote command execution in Microsoft Internet Explorer using .lnk and .url files. |
Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user. |
2Gnu Microsoft4Finger Service FingerdWindows 2000+1 moreApr 16, 2026 Mar 1, 1997 N/A· v4 N/A· v3 0.0 LOW· v2 A version of finger is running that exposes valid user information to any entity on the network. |
Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT. |
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. |
A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories. |
A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdo...Show more |
.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks. |