Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 19307 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0710 1 Microsoft 1 Frontpage 2024-02-04 5.0 MEDIUM N/A
The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.
CVE-2001-0718 1 Microsoft 2 Excel, Powerpoint 2024-02-04 7.5 HIGH N/A
Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.
CVE-2002-0597 1 Microsoft 1 Windows 2000 2024-02-04 5.0 MEDIUM N/A
LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445.
CVE-2003-1275 1 Microsoft 1 Pocket Ie 2024-02-04 5.0 MEDIUM N/A
Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript function that uses the object.innerHTML function to recursively call that function.
CVE-1999-1322 2 Broadcom, Microsoft 3 Arcserve Backup, Inoculan, Exchange Server 2024-02-04 4.6 MEDIUM N/A
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.
CVE-2002-1714 1 Microsoft 2 Ie, Internet Explorer 2024-02-04 5.0 MEDIUM N/A
Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion.
CVE-2000-0400 1 Microsoft 1 Internet Explorer 2024-02-04 7.5 HIGH N/A
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post.
CVE-2001-0137 1 Microsoft 1 Windows Media Player 2024-02-04 5.1 MEDIUM N/A
Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file named skin.wmz, then referencing that skin in the codebase parameter to an applet tag, aka the Windows Media Player Skins File Download" vulnerability.
CVE-1999-0289 2 Apache, Microsoft 2 Http Server, Windows 2024-02-04 5.0 MEDIUM N/A
The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.
CVE-2001-0951 1 Microsoft 1 Windows 2000 2024-02-04 5.0 MEDIUM N/A
Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (IKE) UDP port 500 with packets that contain a large number of dot characters.
CVE-2004-0420 1 Microsoft 2 Ie, Internet Explorer 2024-02-04 10.0 HIGH N/A
The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.
CVE-1999-1581 1 Microsoft 1 Windows Nt 2024-02-04 5.0 MEDIUM N/A
Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large number of SNMP packets with Object Identifiers (OIDs) that cannot be decoded.
CVE-2003-0665 1 Microsoft 1 Access 2024-02-04 7.5 HIGH N/A
Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.
CVE-2003-0347 1 Microsoft 4 Office, Project, Visio and 1 more 2024-02-04 10.0 HIGH N/A
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.
CVE-1999-1578 1 Microsoft 1 Internet Explorer 2024-02-04 5.1 MEDIUM N/A
Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.
CVE-2000-0465 1 Microsoft 1 Internet Explorer 2024-02-04 5.1 MEDIUM N/A
Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability.
CVE-2000-0777 1 Microsoft 1 Money 2024-02-04 7.2 HIGH N/A
The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability.
CVE-2003-0309 1 Microsoft 1 Internet Explorer 2024-02-04 7.5 HIGH N/A
Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."
CVE-2000-0753 1 Microsoft 1 Outlook 2024-02-04 5.0 MEDIUM N/A
The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files.
CVE-2002-0369 1 Microsoft 1 .net Framework 2024-02-04 10.0 HIGH N/A
Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbitrary code via a routine that processes cookies while in StateServer mode.