Windows Explorer
by Microsoft
CVEs (37)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2007-0562 | 0.04 | — | 0.13 | Jan 30, 2007 | Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file. | |||
| CVE-2006-6602 | 0.04 | — | 0.14 | Dec 15, 2006 | explorer.exe in Windows Explorer 6.00.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a crafted WMV file. | |||
| CVE-2005-2117 | 0.03 | — | 0.37 | Oct 21, 2005 | Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code. | |||
| CVE-2006-0012 | 0.02 | — | 0.25 | Apr 12, 2006 | Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability." | |||
| CVE-2007-5145 | 0.01 | — | 0.13 | Oct 1, 2007 | Multiple buffer overflows in system DLL files in Microsoft Windows XP, as used by Microsoft Windows Explorer (explorer.exe) 6.00.2900.2180, Don Ho Notepad++, unspecified Adobe Macromedia applications, and other programs, allow user-assisted remote attackers to cause a denial of… | |||
| CVE-2007-4227 | 0.01 | — | 0.13 | Aug 8, 2007 | Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain JPG file, as demonstrated by something.jpg. NOTE: this issue might be related to CVE-2007-3958. | |||
| CVE-2005-0954 | 0.01 | — | 0.15 | May 2, 2005 | Windows Explorer and Internet Explorer in Windows 2000 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a malformed Windows Metafile (WMF) file. | |||
| CVE-1999-0967 | 0.01 | — | 0.07 | Nov 1, 1997 | Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol. | |||
| CVE-2026-57084 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-50473 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-50456 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-50442 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-50389 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-41087 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-40422 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-33842 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2004-2290 | 0.00 | — | 0.03 | Dec 31, 2004 | Microsoft Windows XP Explorer allows attackers to execute arbitrary code via a HTML and script in a self-executing folder that references an executable file within the folder, which is automatically executed when a user accesses the folder. |
- CVE-2007-0562Jan 30, 2007risk 0.04cvss —epss 0.13
Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file.
- CVE-2006-6602Dec 15, 2006risk 0.04cvss —epss 0.14
explorer.exe in Windows Explorer 6.00.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a crafted WMV file.
- CVE-2005-2117Oct 21, 2005risk 0.03cvss —epss 0.37
Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.
- CVE-2006-0012Apr 12, 2006risk 0.02cvss —epss 0.25
Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."
- CVE-2007-5145Oct 1, 2007risk 0.01cvss —epss 0.13
Multiple buffer overflows in system DLL files in Microsoft Windows XP, as used by Microsoft Windows Explorer (explorer.exe) 6.00.2900.2180, Don Ho Notepad++, unspecified Adobe Macromedia applications, and other programs, allow user-assisted remote attackers to cause a denial of…
- CVE-2007-4227Aug 8, 2007risk 0.01cvss —epss 0.13
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain JPG file, as demonstrated by something.jpg. NOTE: this issue might be related to CVE-2007-3958.
- CVE-2005-0954May 2, 2005risk 0.01cvss —epss 0.15
Windows Explorer and Internet Explorer in Windows 2000 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a malformed Windows Metafile (WMF) file.
- CVE-1999-0967Nov 1, 1997risk 0.01cvss —epss 0.07
Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.
- risk 0.00cvss 5.5epss 0.01
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- CVE-2004-2290Dec 31, 2004risk 0.00cvss —epss 0.03
Microsoft Windows XP Explorer allows attackers to execute arbitrary code via a HTML and script in a self-executing folder that references an executable file within the folder, which is automatically executed when a user accesses the folder.
Page 2 of 2