Microsoft
microsoft
15,661 CVEs • 1,070 products
Products (1,070)
Click to collapseToggle
Products (1,070)
Click to collapse
CVEs (15,661)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 4Ie Internet ExplorerOutlook+1 moreApr 16, 2026 Nov 11, 1999 N/A· v4 N/A· v3 5.1 MEDIUM· v2 A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability. |
The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider. |
Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request. |
2Microsoft Netscape3Ie Internet ExplorerNavigatorApr 16, 2026 Nov 1, 1999 N/A· v4 N/A· v3 2.6 LOW· v2 By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. |
Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Als...Show more |
Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method. |
LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo. |
Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability. |
The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment. |
Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME. |
Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file. |
Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands. |
1Microsoft 1Msn Setup Bulletin Board Services Apr 16, 2026 Sep 24, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured. |
1Microsoft 2Commercial Internet System Internet Information ServerApr 16, 2026 Sep 23, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions. |
1Microsoft 4Terminal Server Windows 95Windows 98se+1 moreApr 16, 2026 Sep 20, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability. |
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager. |
Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account. |
The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration...Show more |
1Microsoft 3Commercial Internet System Site ServerSite Server CommerceApr 16, 2026 Sep 10, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user. |
Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability. |