Microsoft
microsoft
15,656 CVEs • 1,070 products
Products (1,070)
Click to collapseToggle
Products (1,070)
Click to collapse
CVEs (15,656)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1Internet Information Server Apr 16, 2026 Feb 9, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. |
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. |
Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) pac...Show more |
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. |
MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 27, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 27, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jan 26, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 26, 1999 N/A· v4 N/A· v3 7.8 HIGH· v2 The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts. |
Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 24, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command. |
Windows NT 4.0 beta allows users to read and delete shares. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 14, 1999 N/A· v4 N/A· v3 2.1 LOW· v2 When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information...Show more |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 14, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands. |
1Microsoft 3Terminal Server Windows 2000Windows NtApr 16, 2026 Jan 5, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. |
The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. |
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. |
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. |
A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. |
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. |