Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 19327 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0228 1 Microsoft 1 Msn Messenger 2024-02-04 5.0 MEDIUM N/A
Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites).
CVE-2002-0073 1 Microsoft 2 Internet Information Server, Internet Information Services 2024-02-04 5.0 MEDIUM N/A
The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.
CVE-2002-1984 1 Microsoft 1 Internet Explorer 2024-02-04 5.0 MEDIUM N/A
Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".
CVE-1999-1055 1 Microsoft 1 Excel 2024-02-04 7.5 HIGH N/A
Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."
CVE-2002-1705 1 Microsoft 1 Internet Explorer 2024-02-04 5.0 MEDIUM N/A
Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight.
CVE-2004-1244 1 Microsoft 1 Windows Media Player 2024-02-04 7.5 HIGH N/A
Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."
CVE-2000-1090 1 Microsoft 1 Internet Information Server 2024-02-04 5.0 MEDIUM N/A
Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.
CVE-2000-1104 1 Microsoft 2 Internet Information Server, Internet Information Services 2024-02-04 7.5 HIGH N/A
Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.
CVE-2002-0419 1 Microsoft 2 Internet Information Server, Internet Information Services 2024-02-04 5.0 MEDIUM N/A
Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NAT, or (3) when NTLM authentication is used, the NetBIOS name of the server and its Windows NT domain are revealed in response to an Authorization request. NOTE: this entry originally contained a vector (1) in which the server reveals whether it supports Basic or NTLM authentication through 401 Access Denied error messages. CVE has REJECTED this vector; it is not a vulnerability because the information is already available through legitimate use, since authentication cannot proceed without specifying a scheme that is supported by both the client and the server.
CVE-1999-0376 1 Microsoft 1 Windows Nt 2024-02-04 4.6 MEDIUM N/A
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.
CVE-2002-1831 1 Microsoft 1 Msn Messenger 2024-02-04 5.0 MEDIUM N/A
Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.
CVE-1999-0794 1 Microsoft 2 Excel, Office 2024-02-04 4.6 MEDIUM N/A
Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.
CVE-2003-1330 2 Clearswift Limited, Microsoft 2 Mailsweeper, All Windows 2024-02-04 5.0 MEDIUM N/A
Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove.
CVE-1999-0582 1 Microsoft 2 Windows 2000, Windows Nt 2024-02-04 5.0 MEDIUM N/A
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.
CVE-1999-1316 1 Microsoft 1 Windows Nt 2024-02-04 7.5 HIGH N/A
Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.
CVE-1999-0012 2 Microsoft, Netscape 5 Frontpage, Internet Information Server, Personal Web Server and 2 more 2024-02-04 5.0 MEDIUM N/A
Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
CVE-1999-0716 1 Microsoft 2 Windows 2000, Windows Nt 2024-02-04 4.6 MEDIUM N/A
Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.
CVE-2000-0160 1 Microsoft 3 Ie, Internet Explorer, Outlook 2024-02-04 7.6 HIGH N/A
The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.
CVE-2003-0820 1 Microsoft 2 Word, Works 2024-02-04 7.5 HIGH N/A
Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.
CVE-1999-1084 1 Microsoft 1 Windows Nt 2024-02-04 4.6 MEDIUM N/A
The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.