Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 19372 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0339 1 Microsoft 1 Internet Explorer 2024-02-04 7.5 HIGH N/A
Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."
CVE-2004-0214 1 Microsoft 5 Internet Explorer, Windows 2000, Windows 98 and 2 more 2024-02-04 10.0 HIGH N/A
Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
CVE-2000-0849 1 Microsoft 1 Windows Media Services 2024-02-04 2.6 LOW N/A
Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.
CVE-2002-0057 1 Microsoft 4 Internet Explorer, Sql Server, Windows Xp and 1 more 2024-02-04 5.0 MEDIUM N/A
XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
CVE-2003-0232 1 Microsoft 2 Data Engine, Sql Server 2024-02-04 7.2 HIGH N/A
Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.
CVE-2000-0260 1 Microsoft 2 Frontpage, Visual Interdev 2024-02-04 7.5 HIGH N/A
Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link View Server-Side Component" vulnerability.
CVE-2002-2077 1 Microsoft 1 Windows 2000 2024-02-04 5.0 MEDIUM N/A
The DCOM client in Windows 2000 before SP3 does not properly clear memory before sending an "alter context" request, which may allow remote attackers to obtain sensitive information by sniffing the session.
CVE-2004-1324 1 Microsoft 1 Windows Media Player 2024-02-04 2.6 LOW N/A
The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the Local computer zone via the (1) artist or (2) song fields of a music file, if the file is processed using Internet Explorer.
CVE-2001-0333 1 Microsoft 1 Internet Information Server 2024-02-04 7.5 HIGH N/A
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.
CVE-2004-0847 1 Microsoft 1 Asp.net 2024-02-04 7.5 HIGH 9.8 CRITICAL
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."
CVE-2000-1112 1 Microsoft 1 Windows Media Player 2024-02-04 4.6 MEDIUM N/A
Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.
CVE-1999-0386 1 Microsoft 2 Frontpage, Personal Web Server 2024-02-04 5.0 MEDIUM N/A
Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.
CVE-2003-0348 1 Microsoft 1 Windows Media Player 2024-02-04 6.4 MEDIUM N/A
A certain Microsoft Windows Media Player 9 Series ActiveX control allows remote attackers to view and manipulate the Media Library on the local system via HTML script.
CVE-2003-0306 1 Microsoft 1 Windows Xp 2024-02-04 7.2 HIGH N/A
Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.
CVE-2002-0021 1 Microsoft 1 Office 2024-02-04 5.0 MEDIUM N/A
Network Product Identification (PID) Checker in Microsoft Office v. X for Mac allows remote attackers to cause a denial of service (crash) via a malformed product announcement.
CVE-2001-0146 1 Microsoft 2 Exchange Server, Internet Information Services 2024-02-04 5.0 MEDIUM N/A
IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
CVE-2000-0416 1 Microsoft 1 Windows 2000 2024-02-04 5.0 MEDIUM N/A
NTMail 5.x allows network users to bypass the NTMail proxy restrictions by redirecting their requests to NTMail's web configuration server.
CVE-1999-1223 1 Microsoft 1 Internet Information Server 2024-02-04 5.0 MEDIUM N/A
IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.
CVE-1999-0585 1 Microsoft 2 Windows 2000, Windows Nt 2024-02-04 2.1 LOW N/A
A Windows NT administrator account has the default name of Administrator.
CVE-2003-1448 1 Microsoft 1 Windows 2000 2024-02-04 7.8 HIGH N/A
Memory leak in the Windows 2000 kernel allows remote attackers to cause a denial of service (SMB request hang) via a NetBIOS continuation packet.