Windows
by Microsoft
CVEs (2,653)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2001-0238 | 0.01 | — | 0.15 | Jul 2, 2001 | Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests. | |||
| CVE-2000-0980 | 0.01 | — | 0.13 | Dec 19, 2000 | NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network. | |||
| CVE-2000-1003 | 0.01 | — | 0.13 | Dec 11, 2000 | NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash. | |||
| CVE-2000-1079 | 0.01 | — | 0.16 | Aug 29, 2000 | Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram. | |||
| CVE-2000-0612 | 0.01 | — | 0.09 | Jun 29, 2000 | Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table. | |||
| CVE-2000-0404 | 0.01 | — | 0.18 | May 25, 2000 | The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability. | |||
| CVE-1999-0387 | 0.01 | — | 0.08 | Nov 29, 1999 | A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords. | |||
| CVE-1999-0909 | 0.01 | — | 0.12 | Sep 20, 1999 | Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability. | |||
| CVE-1999-0444 | 0.01 | — | 0.16 | Apr 12, 1999 | Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files. | |||
| CVE-1999-1254 | 0.01 | — | 0.13 | Mar 8, 1999 | Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables. | |||
| CVE-1999-1201 | 0.01 | — | 0.14 | Feb 6, 1999 | Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka… | |||
| CVE-1999-1291 | 0.01 | — | 0.13 | Oct 5, 1998 | TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to… | |||
| CVE-1999-0104 | 0.01 | — | 0.09 | Dec 16, 1997 | A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2. | |||
| CVE-2026-56190 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-56186 | Hig | 0.00 | 8.1 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-54126 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-54115 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50690 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. | ||
| CVE-2026-50686 | Hig | 0.00 | 8.1 | 0.01 | Jul 14, 2026 | Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-50500 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. |
- CVE-2001-0238Jul 2, 2001risk 0.01cvss —epss 0.15
Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.
- CVE-2000-0980Dec 19, 2000risk 0.01cvss —epss 0.13
NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network.
- CVE-2000-1003Dec 11, 2000risk 0.01cvss —epss 0.13
NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash.
- CVE-2000-1079Aug 29, 2000risk 0.01cvss —epss 0.16
Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.
- CVE-2000-0612Jun 29, 2000risk 0.01cvss —epss 0.09
Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table.
- CVE-2000-0404May 25, 2000risk 0.01cvss —epss 0.18
The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability.
- CVE-1999-0387Nov 29, 1999risk 0.01cvss —epss 0.08
A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.
- CVE-1999-0909Sep 20, 1999risk 0.01cvss —epss 0.12
Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.
- CVE-1999-0444Apr 12, 1999risk 0.01cvss —epss 0.16
Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.
- CVE-1999-1254Mar 8, 1999risk 0.01cvss —epss 0.13
Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.
- CVE-1999-1201Feb 6, 1999risk 0.01cvss —epss 0.14
Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka…
- CVE-1999-1291Oct 5, 1998risk 0.01cvss —epss 0.13
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to…
- CVE-1999-0104Dec 16, 1997risk 0.01cvss —epss 0.09
A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.
- risk 0.00cvss 9.8epss 0.01
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.1epss 0.01
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
- risk 0.00cvss 6.5epss 0.01
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
- risk 0.00cvss 7.8epss 0.00
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.5epss 0.00
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
- risk 0.00cvss 8.1epss 0.01
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 7.5epss 0.01
Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.
Page 120 of 133