VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-1999-0750Sep 13, 1999
    risk 0.04cvss epss 0.09

    Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account.

  • CVE-1999-0669Sep 1, 1999
    risk 0.04cvss epss 0.09

    The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.

  • CVE-1999-1016Aug 27, 1999
    risk 0.04cvss epss 0.08

    Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as…

  • CVE-1999-0749Aug 16, 1999
    risk 0.04cvss epss 0.08

    Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.

  • CVE-1999-0875Aug 11, 1999
    risk 0.04cvss epss 0.10

    DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.

  • CVE-1999-0224Jul 23, 1999
    risk 0.04cvss epss 0.17

    Denial of service in Windows NT messenger service through a long username.

  • CVE-1999-0140Jun 30, 1999
    risk 0.04cvss epss 0.14

    Denial of service in RAS/PPTP on NT systems.

  • CVE-1999-0755May 27, 1999
    risk 0.04cvss epss 0.15

    Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.

  • CVE-1999-1033May 11, 1999
    risk 0.04cvss epss 0.17

    Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang.

  • CVE-1999-1520May 11, 1999
    risk 0.04cvss epss 0.12

    A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.

  • CVE-1999-0487May 1, 1999
    risk 0.04cvss epss 0.13

    The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.

  • CVE-1999-0412Feb 19, 1999
    risk 0.04cvss epss 0.10

    In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.

  • CVE-1999-1453Feb 2, 1999
    risk 0.04cvss epss 0.11

    Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.

  • CVE-1999-0449Jan 26, 1999
    risk 0.04cvss epss 0.50

    The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.

  • CVE-1999-0450Jan 26, 1999
    risk 0.04cvss epss 0.19

    In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).

  • CVE-1999-0869Dec 1, 1998
    risk 0.04cvss epss 0.17

    Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.

  • CVE-1999-0506Oct 1, 1998
    risk 0.04cvss epss 0.17

    A Windows NT domain user or administrator account has a default, null, blank, or missing password.

  • CVE-1999-0284Jan 1, 1998
    risk 0.04cvss epss 0.12

    Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.

  • CVE-1999-0294Oct 1, 1997
    risk 0.04cvss epss 0.15

    All records in a WINS database can be deleted through SNMP for a denial of service.

  • CVE-1999-0281Jun 1, 1997
    risk 0.04cvss epss 0.13

    Denial of service in IIS using long URLs.

  • CVE-1999-0562Jan 1, 1997
    risk 0.04cvss epss 0.10

    The registry in Windows NT can be accessed remotely by users who are not administrators.

  • CVE-1999-0233Feb 25, 1996
    risk 0.04cvss epss 0.16

    IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.

  • CVE-2015-6174Dec 9, 2015
    risk 0.03cvss epss 0.03

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka…

  • CVE-2015-6173Dec 9, 2015
    risk 0.03cvss epss 0.03

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka…

  • CVE-2015-6171Dec 9, 2015
    risk 0.03cvss epss 0.03

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka…

  • CVE-2015-6102Nov 11, 2015
    risk 0.03cvss epss 0.04

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and…

  • CVE-2015-6101Nov 11, 2015
    risk 0.03cvss epss 0.03

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka…

  • CVE-2015-6100Nov 11, 2015
    risk 0.03cvss epss 0.03

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka…

  • CVE-2015-6098Nov 11, 2015
    risk 0.03cvss epss 0.04

    Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows NDIS Elevation of Privilege…

  • CVE-2015-6038Nov 11, 2015
    risk 0.03cvss epss 0.36

    Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3, 2010 SP2, and 2013 SP1 allow remote attackers to…

  • CVE-2015-2554Oct 14, 2015
    risk 0.03cvss epss 0.04

    The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Object Reference Elevation of Privilege Vulnerability."

  • CVE-2015-2553Oct 14, 2015
    risk 0.03cvss epss 0.03

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles junctions during mountpoint creation, which makes it easier for local users…

  • CVE-2015-2528Sep 9, 2015
    risk 0.03cvss epss 0.04

    Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Elevation of Privilege…

  • CVE-2015-2524Sep 9, 2015
    risk 0.03cvss epss 0.03

    Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Elevation of Privilege…

  • CVE-2015-2518Sep 9, 2015
    risk 0.03cvss epss 0.04

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k…

  • CVE-2015-2517Sep 9, 2015
    risk 0.03cvss epss 0.04

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k…

  • CVE-2015-2512Sep 9, 2015
    risk 0.03cvss epss 0.04

    The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka…

  • CVE-2015-2511Sep 9, 2015
    risk 0.03cvss epss 0.04

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k…

  • CVE-2015-2508Sep 9, 2015
    risk 0.03cvss epss 0.04

    The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of Privilege Vulnerability."

  • CVE-2015-2507Sep 9, 2015
    risk 0.03cvss epss 0.04

    The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka…

  • CVE-2015-2370Jul 14, 2015
    risk 0.03cvss epss 0.04

    The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not prevent…

  • CVE-2015-2366Jul 14, 2015
    risk 0.03cvss epss 0.03

    win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege…

  • CVE-2015-2365Jul 14, 2015
    risk 0.03cvss epss 0.03

    win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges…

  • CVE-2015-2373Jul 14, 2015
    risk 0.03cvss epss 0.38

    The Remote Desktop Protocol (RDP) server service in Microsoft Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a series of crafted packets, aka "Remote Desktop Protocol (RDP) Remote Code Execution Vulnerability."

  • CVE-2015-1727Jun 10, 2015
    risk 0.03cvss epss 0.03

    Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain…

  • CVE-2015-1726Jun 10, 2015
    risk 0.03cvss epss 0.03

    Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users…

  • CVE-2015-1725Jun 10, 2015
    risk 0.03cvss epss 0.04

    Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain…

  • CVE-2015-1724Jun 10, 2015
    risk 0.03cvss epss 0.03

    Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users…

  • CVE-2015-1723Jun 10, 2015
    risk 0.03cvss epss 0.03

    Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users…

  • CVE-2015-1722Jun 10, 2015
    risk 0.03cvss epss 0.03

    Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users…

Page 239 of 314