VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2000-0942Dec 19, 2000
    risk 0.05cvss epss 0.22

    The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.

  • CVE-2000-0983Dec 19, 2000
    risk 0.05cvss epss 0.21

    Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability.

  • CVE-2000-0830Nov 14, 2000
    risk 0.05cvss epss 0.26

    annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP packet to ports 22701 through 22705.

  • CVE-2000-0653Jul 20, 2000
    risk 0.05cvss epss 0.27

    Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.

  • CVE-2000-0581Jun 30, 2000
    risk 0.05cvss epss 0.22

    Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash.

  • CVE-2000-0377Jun 8, 2000
    risk 0.05cvss epss 0.19

    The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability.

  • CVE-2000-0465May 17, 2000
    risk 0.05cvss epss 0.20

    Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability.

  • CVE-1999-0980May 16, 2000
    risk 0.05cvss epss 0.23

    Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request.

  • CVE-2000-0457May 11, 2000
    risk 0.05cvss epss 0.53

    ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.

  • CVE-2000-0168Mar 4, 2000
    risk 0.05cvss epss 0.20

    Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability.

  • CVE-2000-0211Feb 23, 2000
    risk 0.05cvss epss 0.21

    The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerability.

  • CVE-2000-0105Feb 1, 2000
    risk 0.05cvss epss 0.21

    Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client.

  • CVE-2000-0132Jan 31, 2000
    risk 0.05cvss epss 0.19

    Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.

  • CVE-2000-0061Jan 7, 2000
    risk 0.05cvss epss 0.20

    Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.

  • CVE-2000-0028Dec 23, 1999
    risk 0.05cvss epss 0.23

    Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.

  • CVE-1999-0999Nov 19, 1999
    risk 0.05cvss epss 0.22

    Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.

  • CVE-2000-0073Nov 17, 1999
    risk 0.05cvss epss 0.21

    Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.

  • CVE-1999-1577Oct 31, 1999
    risk 0.05cvss epss 0.19

    Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.

  • CVE-1999-1484Sep 24, 1999
    risk 0.05cvss epss 0.27

    Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.

  • CVE-1999-1578Sep 24, 1999
    risk 0.05cvss epss 0.19

    Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.

  • CVE-1999-0886Sep 17, 1999
    risk 0.05cvss epss 0.22

    The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.

  • CVE-1999-0702Sep 10, 1999
    risk 0.05cvss epss 0.24

    Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.

  • CVE-1999-0668Aug 21, 1999
    risk 0.05cvss epss 0.23

    The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.

  • CVE-1999-0725Aug 19, 1999
    risk 0.05cvss epss 0.25

    When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".

  • CVE-1999-0867Aug 11, 1999
    risk 0.05cvss epss 0.22

    Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.

  • CVE-1999-0918Jul 3, 1999
    risk 0.05cvss epss 0.26

    Denial of service in various Windows systems via malformed, fragmented IGMP packets.

  • CVE-1999-0386Mar 1, 1999
    risk 0.05cvss epss 0.19

    Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.

  • CVE-1999-1375Feb 11, 1999
    risk 0.05cvss epss 0.31

    FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.

  • CVE-1999-1538Jan 14, 1999
    risk 0.05cvss epss 0.25

    When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.

  • CVE-1999-0448Jan 1, 1999
    risk 0.05cvss epss 0.25

    IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.

  • CVE-1999-0288Aug 1, 1998
    risk 0.05cvss epss 0.21

    The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.

  • CVE-1999-0153Jul 1, 1997
    risk 0.05cvss epss 0.21

    Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.

  • CVE-1999-0612Mar 1, 1997
    risk 0.05cvss epss 0.67

    A version of finger is running that exposes valid user information to any entity on the network.

  • CVE-1999-0077Jan 1, 1995
    risk 0.05cvss epss 0.31

    Predictable TCP sequence numbers allow spoofing.

  • CVE-2015-6176Dec 9, 2015
    risk 0.04cvss epss 0.13

    Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Edge XSS Filter Bypass Vulnerability."

  • CVE-2015-6172Dec 9, 2015
    risk 0.04cvss epss 0.54

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted email message processed by Outlook, aka "Microsoft Office RCE Vulnerability."

  • CVE-2015-6099Nov 11, 2015
    risk 0.04cvss epss 0.48

    Cross-site scripting (XSS) vulnerability in ASP.NET in Microsoft .NET Framework 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka ".NET Elevation of Privilege Vulnerability."

  • CVE-2015-2527Sep 9, 2015
    risk 0.04cvss epss 0.07

    The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 does not properly constrain impersonation levels, which allows local users to gain…

  • CVE-2015-2433Aug 15, 2015
    risk 0.04cvss epss 0.17

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application,…

  • CVE-2015-0059Feb 11, 2015
    risk 0.04cvss epss 0.11

    win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted TrueType font, aka "TrueType Font Parsing Remote…

  • CVE-2015-0057Feb 11, 2015
    risk 0.04cvss epss 0.13

    win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a…

  • CVE-2015-0009Feb 11, 2015
    risk 0.04cvss epss 0.08

    The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows man-in-the-middle…

  • CVE-2015-0002Jan 13, 2015
    risk 0.04cvss epss 0.14

    The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify that an impersonation token…

  • CVE-2014-1767Jul 8, 2014
    risk 0.04cvss epss 0.13

    Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows…

  • CVE-2014-1823Jun 11, 2014
    risk 0.04cvss epss 0.51

    Cross-site scripting (XSS) vulnerability in the Web Components Server in Microsoft Lync Server 2010 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containing a valid meeting ID, aka "Lync Server Content Sanitization Vulnerability."

  • CVE-2014-1778Jun 11, 2014
    risk 0.04cvss epss 0.15

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-2777.

  • CVE-2014-1771Jun 11, 2014
    risk 0.04cvss epss 0.08

    SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a…

  • CVE-2013-4858Dec 30, 2013
    risk 0.04cvss epss 0.13

    Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav file, as demonstrated by movieMaker.wav.

  • CVE-2013-5045Dec 11, 2013
    risk 0.04cvss epss 0.17

    Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."

  • CVE-2013-3881Oct 9, 2013
    risk 0.04cvss epss 0.15

    win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to gain privileges via a crafted application, aka "Win32k NULL Page Vulnerability."

Page 234 of 314