Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 19327 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0790 1 Microsoft 3 Windows 2000, Windows 98, Windows 98se 2024-02-04 4.6 MEDIUM N/A
The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option for the first file that is listed in the folder.
CVE-2003-0109 1 Microsoft 2 Windows 2000, Windows 2000 Terminal Services 2024-02-04 7.5 HIGH N/A
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
CVE-1999-0969 1 Microsoft 1 Windows Nt 2024-02-04 5.0 MEDIUM N/A
The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.
CVE-2003-0821 1 Microsoft 2 Word, Works 2024-02-04 7.5 HIGH N/A
Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.
CVE-1999-0274 1 Microsoft 1 Windows Nt 2024-02-04 5.0 MEDIUM N/A
Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.
CVE-2002-0980 1 Microsoft 1 Internet Explorer 2024-02-04 7.5 HIGH N/A
The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL.
CVE-1999-0379 1 Microsoft 1 Backoffice Resource Kit 2024-02-04 7.5 HIGH N/A
Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.
CVE-2003-1372 4 Linux, Microsoft, Myphpnuke and 1 more 4 Linux Kernel, All Windows, Myphpnuke and 1 more 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters.
CVE-1999-0876 1 Microsoft 2 Ie, Internet Explorer 2024-02-04 10.0 HIGH N/A
Buffer overflow in Internet Explorer 4.0 via EMBED tag.
CVE-1999-0577 1 Microsoft 1 Windows Nt 2024-02-04 10.0 HIGH N/A
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
CVE-1999-1370 1 Microsoft 1 Internet Explorer 2024-02-04 7.2 HIGH N/A
The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs.
CVE-2000-0402 1 Microsoft 1 Sql Server 2024-02-04 2.1 LOW N/A
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.
CVE-2001-0246 1 Microsoft 1 Internet Explorer 2024-02-04 5.0 MEDIUM N/A
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability.
CVE-2002-1671 1 Microsoft 1 Internet Explorer 2024-02-04 5.0 MEDIUM N/A
Microsoft Internet Explorer 5.0, 5.01, and 5.5 allows remote attackers to monitor the contents of the clipboard via the getData method of the clipboardData object.
CVE-2004-0841 2 Avaya, Microsoft 7 Definity One Media Server, Ip600 Media Servers, Modular Messaging Message Storage Server and 4 more 2024-02-04 5.0 MEDIUM N/A
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
CVE-2004-0526 1 Microsoft 4 Ie, Internet Explorer, Outlook and 1 more 2024-02-04 5.0 MEDIUM N/A
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
CVE-2000-0858 1 Microsoft 2 Internet Information Server, Windows Nt 2024-02-04 5.0 MEDIUM N/A
Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability.
CVE-2002-0724 1 Microsoft 3 Windows 2000, Windows Nt, Windows Xp 2024-02-04 7.5 HIGH N/A
Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".
CVE-1999-0104 4 Caldera, Hp, Microsoft and 1 more 5 Openlinux, Hp-ux, Windows 95 and 2 more 2024-02-04 5.0 MEDIUM N/A
A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.
CVE-2004-0123 1 Microsoft 7 Windows 2000, Windows 2003 Server, Windows 98 and 4 more 2024-02-04 7.5 HIGH N/A
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.