Microsoft
microsoft
15,661 CVEs • 1,070 products
Products (1,070)
Click to collapseToggle
Products (1,070)
Click to collapse
CVEs (15,661)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability. |
1Microsoft 3Internet Information Server Site ServerSite Server CommerceApr 16, 2026 Dec 21, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory...Show more |
1Microsoft 3Internet Information Server Site ServerSite Server CommerceApr 16, 2026 Dec 21, 1999 N/A· v4 N/A· v3 6.4 MEDIUM· v2 IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability. |
Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request." |
Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords. |
Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed. |
1Microsoft 3Windows 95 Windows 98Windows NtApr 16, 2026 Dec 10, 1999 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when...Show more |
Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect." |
Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol. |
Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server. |
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it. |
A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users. |
Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled. |
A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords. |
Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet. |
Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name. |
1Microsoft 3Windows 2000 Windows 98Windows NtApr 16, 2026 Nov 17, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word. |
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. |
Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client. |
The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability. |