← Back

Microsoft

microsoft

16,005 CVEs • 1,072 products

Products (1,072)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
365 Apps
365_apps
Edge
edge
Windows Xp
windows_xp
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Office 2021
office_2021
Office 2024
office_2024
Office 2019
office_2019
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2016
office_2016
.net
Dynamics 365
dynamics_365
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Access
access

CVEs (16,005)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Broadcom
Microsoft
3Arcserve Backup
Exchange ServerInoculan
Apr 16, 2026
Nov 12, 1998
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.
1Microsoft
2Windows 95
Windows Nt
Apr 16, 2026
Oct 5, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence...Show more
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Oct 1, 1998
N/A· v4
N/A· v3
2.6 LOW· v2
Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.
1Microsoft
1Windows Nt
Apr 16, 2026
Oct 1, 1998
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Windows NT guest account is enabled.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Oct 1, 1998
N/A· v4
N/A· v3
7.2 HIGH· v2
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Oct 1, 1998
N/A· v4
N/A· v3
7.2 HIGH· v2
A Windows NT domain user or administrator account has a guessable password.
1Microsoft
1Windows Nt
Apr 16, 2026
Sep 29, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka S...Show more
The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Sep 4, 1998
N/A· v4
N/A· v3
2.6 LOW· v2
Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.
1Microsoft
1Windows Nt
Apr 16, 2026
Aug 1, 1998
N/A· v4
N/A· v3
7.2 HIGH· v2
NT users can gain debug-level access on a system process using the Sechole exploit.
1Microsoft
1Windows Nt
Apr 16, 2026
Aug 1, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of...Show more
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Jul 28, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.
1Microsoft
1Sql Server
Apr 16, 2026
Jun 29, 1998
N/A· v4
N/A· v3
7.2 HIGH· v2
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and d...Show more
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.Show less
5C2net
HpMicrosoft+2 more
13Certificate Server
Collabra ServerDirectory Server+10 more
Apr 16, 2026
Jun 26, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Information from SSL-encrypted sessions via PKCS #1.
1Microsoft
2Internet Information Server
Windows Nt
Apr 16, 2026
Jun 1, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
1Microsoft
1Windows Nt
Apr 16, 2026
May 9, 1998
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and f...Show more
Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages.Show less
2Microsoft
Netscape
2Communicator
Internet Explorer
Apr 16, 2026
Apr 1, 1998
N/A· v4
N/A· v3
7.5 HIGH· v2
A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.
1Microsoft
1Windows Nt
Apr 16, 2026
Feb 14, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.
1Microsoft
2Windows 95
Windows Nt
Apr 16, 2026
Feb 13, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Bonk variation of teardrop IP fragmentation denial of service.
2Microsoft
Netscape
5Enterprise Server
Fasttrack ServerFrontpage+2 more
Apr 16, 2026
Feb 6, 1998
N/A· v4
7.0 HIGH· v3
5.0 MEDIUM· v2
Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
2Jgaa
Microsoft
3Warftpd
Windows 95Windows Nt
Apr 16, 2026
Feb 1, 1998
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in War FTP allows remote execution of commands.