Microsoft
microsoft
15,656 CVEs • 1,070 products
Products (1,070)
Click to collapseToggle
Products (1,070)
Click to collapse
CVEs (15,656)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. |
A system-critical Windows NT file or directory has inappropriate permissions. |
Windows NT automatically logs in an administrator upon rebooting. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 1, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. |
1Microsoft 6Office OutlookProject+3 moreApr 16, 2026 Jan 1, 1999 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content. |
2Fms Inc. Microsoft2Access Total Vb SourcebookApr 16, 2026 Jan 1, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data. |
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection. |
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service. |
2Microsoft Netscape2Internet Explorer NavigatorApr 16, 2026 Dec 1, 1998 N/A· v4 N/A· v3 2.6 LOW· v2 Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing. |
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. |
Buffer overflow in NetMeeting allows denial of service and remote command execution. |
2Broadcom Microsoft3Arcserve Backup Exchange ServerInoculanApr 16, 2026 Nov 12, 1998 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext. |
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence...Show more |
Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste. |
The Windows NT guest account is enabled. |
A Windows NT domain user or administrator account has a default, null, blank, or missing password. |
A Windows NT domain user or administrator account has a guessable password. |
The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka S...Show more |
Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability. |
NT users can gain debug-level access on a system process using the Sechole exploit. |