Microsoft
microsoft
16,005 CVEs • 1,072 products
Products (1,072)
Click to collapseToggle
Products (1,072)
Click to collapse
CVEs (16,005)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Windows NT 4.0 beta allows users to read and delete shares. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 14, 1999 N/A· v4 N/A· v3 2.1 LOW· v2 When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information...Show more |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 14, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands. |
1Microsoft 3Terminal Server Windows 2000Windows NtApr 16, 2026 Jan 5, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. |
The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. |
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. |
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. |
A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. |
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. |
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. |
A system-critical Windows NT file or directory has inappropriate permissions. |
Windows NT automatically logs in an administrator upon rebooting. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 1, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. |
1Microsoft 6Office OutlookProject+3 moreApr 16, 2026 Jan 1, 1999 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content. |
2Fms Inc. Microsoft2Access Total Vb SourcebookApr 16, 2026 Jan 1, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data. |
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection. |
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service. |
2Microsoft Netscape2Internet Explorer NavigatorApr 16, 2026 Dec 1, 1998 N/A· v4 N/A· v3 2.6 LOW· v2 Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing. |
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. |
Buffer overflow in NetMeeting allows denial of service and remote command execution. |