Microsoft
microsoft
15,661 CVEs • 1,070 products
Products (1,070)
Click to collapseToggle
Products (1,070)
Click to collapse
CVEs (15,661)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect. |
Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands. |
The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. |
2Microsoft Qualcomm4Eudora FrontpageInternet Explorer+1 moreApr 16, 2026 Aug 27, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service...Show more |
Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observ...Show more |
Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking. |
Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive informati...Show more |
The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. |
The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability. |
1Microsoft 1Internet Information Server Apr 16, 2026 Aug 19, 1999 N/A· v4 N/A· v3 7.1 HIGH· v2 When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". |
Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument. |
2Microsoft Sun5Solaris SunosWindows 2000+2 moreApr 16, 2026 Aug 11, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes. |
1Microsoft 3Commercial Internet System Internet Information ServerSite ServerApr 16, 2026 Aug 11, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. |
1Microsoft 4Commercial Internet System Internet Information ServerSite Server+1 moreApr 16, 2026 Aug 11, 1999 N/A· v4 N/A· v3 2.6 LOW· v2 Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. |
Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service. |
Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled. |
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file. |
The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability. |
Denial of service in Windows NT messenger service through a long username. |
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request. |