← Back

Microsoft

microsoft

15,661 CVEs • 1,070 products

Products (1,070)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Office 2021
office_2021
Office 2024
office_2024
Office 2019
office_2019
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
.net
Dynamics 365
dynamics_365
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Office 2016
office_2016
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Access
access

CVEs (15,661)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
4Ie
Internet ExplorerOutlook+1 more
Apr 16, 2026
Nov 11, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.
1Microsoft
1Windows Nt
Apr 16, 2026
Nov 4, 1999
N/A· v4
N/A· v3
7.2 HIGH· v2
The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.
1Microsoft
1Windows Nt
Apr 16, 2026
Nov 4, 1999
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.
2Microsoft
Netscape
3Ie
Internet ExplorerNavigator
Apr 16, 2026
Nov 1, 1999
N/A· v4
N/A· v3
2.6 LOW· v2
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.
1Microsoft
2Internet Explorer
Word
Apr 16, 2026
Nov 1, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Als...Show more
Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Oct 31, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.
1Microsoft
1Windows Nt
Apr 16, 2026
Oct 26, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.
1Microsoft
1Virtual Machine
Apr 16, 2026
Oct 21, 1999
N/A· v4
N/A· v3
7.6 HIGH· v2
Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability.
1Microsoft
1Java Virtual Machine
Apr 16, 2026
Oct 21, 1999
N/A· v4
N/A· v3
9.3 HIGH· v2
The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.
1Microsoft
1Internet Explorer
Apr 16, 2026
Oct 1, 1999
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.
1Microsoft
1Excel
Apr 16, 2026
Oct 1, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.
1Microsoft
1Internet Explorer
Apr 16, 2026
Sep 24, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.
1Microsoft
1Msn Setup Bulletin Board Services
Apr 16, 2026
Sep 24, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.
1Microsoft
2Commercial Internet System
Internet Information Server
Apr 16, 2026
Sep 23, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.
1Microsoft
4Terminal Server
Windows 95Windows 98se+1 more
Apr 16, 2026
Sep 20, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.
1Microsoft
1Windows Nt
Apr 16, 2026
Sep 17, 1999
N/A· v4
N/A· v3
9.0 HIGH· v2
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
1Microsoft
1Hotmail
Apr 16, 2026
Sep 13, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account.
1Microsoft
1Internet Explorer
Apr 16, 2026
Sep 10, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration...Show more
The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active Setup (setupctl.dll) ActiveX controls for Internet Explorer (IE) 4.01 and 5.0 are marked as "Safe for Scripting," which allows remote attackers to create and modify files and execute arbitrary commands.Show less
1Microsoft
3Commercial Internet System
Site ServerSite Server Commerce
Apr 16, 2026
Sep 10, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.
1Microsoft
1Internet Explorer
Apr 16, 2026
Sep 10, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.