VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2000-0710Oct 20, 2000
    risk 0.02cvss epss 0.26

    The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.

  • CVE-2000-0709Oct 20, 2000
    risk 0.02cvss epss 0.25

    The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.

  • CVE-2000-0742Oct 20, 2000
    risk 0.02cvss epss 0.19

    The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability.

  • CVE-2000-0621Jul 20, 2000
    risk 0.02cvss epss 0.22

    Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.

  • CVE-2000-0662Jul 14, 2000
    risk 0.02cvss epss 0.21

    Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).

  • CVE-2000-0631Jul 14, 2000
    risk 0.02cvss epss 0.25

    An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability.

  • CVE-2000-0596Jun 27, 2000
    risk 0.02cvss epss 0.25

    Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.

  • CVE-2000-0419May 11, 2000
    risk 0.02cvss epss 0.21

    The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.

  • CVE-2000-0304May 10, 2000
    risk 0.02cvss epss 0.29

    Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.

  • CVE-2000-0122Feb 3, 2000
    risk 0.02cvss epss 0.21

    Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program.

  • CVE-2000-0081Jan 10, 2000
    risk 0.02cvss epss 0.19

    Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript.

  • CVE-1999-1105Dec 31, 1999
    risk 0.02cvss epss 0.22

    Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive.

  • CVE-1999-1223Dec 31, 1999
    risk 0.02cvss epss 0.23

    IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.

  • CVE-1999-0995Dec 16, 1999
    risk 0.02cvss epss 0.22

    Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request."

  • CVE-2000-0328Aug 24, 1999
    risk 0.02cvss epss 0.25

    Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.

  • CVE-1999-0682Aug 6, 1999
    risk 0.02cvss epss 0.26

    Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.

  • CVE-1999-0739May 7, 1999
    risk 0.02cvss epss 0.29

    The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

  • CVE-1999-0738May 7, 1999
    risk 0.02cvss epss 0.29

    The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

  • CVE-1999-0737May 7, 1999
    risk 0.02cvss epss 0.28

    The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

  • CVE-1999-1376Jan 14, 1999
    risk 0.02cvss epss 0.24

    Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.

  • CVE-1999-1581Dec 23, 1997
    risk 0.02cvss epss 0.21

    Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large number of SNMP packets with Object Identifiers (OIDs) that cannot be decoded.

  • CVE-1999-1387Apr 2, 1997
    risk 0.02cvss epss 0.21

    Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.

  • CVE-2026-50518CriJul 14, 2026
    risk 0.01cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

  • CVE-2024-25110CriFeb 12, 2024
    risk 0.01cvss 9.8epss 0.07

    The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to…

  • CVE-2020-1045HigSep 11, 2020
    risk 0.01cvss 7.5epss 0.06

    A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names. The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent…

  • CVE-2020-0812HigMar 12, 2020
    risk 0.01cvss 7.5epss 0.08

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)L, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0811.

  • CVE-2020-0811HigMar 12, 2020
    risk 0.01cvss 7.5epss 0.08

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)L, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0812.

  • CVE-2020-0767HigFeb 11, 2020
    risk 0.01cvss 7.5epss 0.18

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712,…

  • CVE-2020-0713HigFeb 11, 2020
    risk 0.01cvss 7.5epss 0.10

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712,…

  • CVE-2020-0711HigFeb 11, 2020
    risk 0.01cvss 7.5epss 0.10

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-2020-0710, CVE-2020-0712, CVE-2020-0713,…

  • CVE-2020-0710HigFeb 11, 2020
    risk 0.01cvss 7.5epss 0.10

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713,…

  • CVE-2015-6177Dec 9, 2015
    risk 0.01cvss epss 0.14

    Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

  • CVE-2015-6170Dec 9, 2015
    risk 0.01cvss epss 0.09

    Microsoft Edge allows remote attackers to gain privileges via a crafted web site, aka "Microsoft Browser Elevation of Privilege Vulnerability."

  • CVE-2015-6169Dec 9, 2015
    risk 0.01cvss epss 0.09

    Microsoft Edge misparses HTTP responses, which allows remote attackers to redirect users to arbitrary web sites via unspecified vectors, aka "Microsoft Edge Spoofing Vulnerability."

  • CVE-2015-6166Dec 9, 2015
    risk 0.01cvss epss 0.14

    Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read or write access) via unspecified open and close requests, aka "Microsoft Silverlight RCE Vulnerability."

  • CVE-2015-6165Dec 9, 2015
    risk 0.01cvss epss 0.16

    Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Silverlight Information Disclosure Vulnerability," a different vulnerability than CVE-2015-6114.

  • CVE-2015-6164Dec 9, 2015
    risk 0.01cvss epss 0.12

    Microsoft Internet Explorer 9 through 11 improperly implements a cross-site scripting (XSS) protection mechanism, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, aka "Internet Explorer XSS Filter Bypass Vulnerability."

  • CVE-2015-6162Dec 9, 2015
    risk 0.01cvss epss 0.13

    Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6152.

  • CVE-2015-6158Dec 9, 2015
    risk 0.01cvss epss 0.17

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140,…

  • CVE-2015-6157Dec 9, 2015
    risk 0.01cvss epss 0.16

    Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

  • CVE-2015-6156Dec 9, 2015
    risk 0.01cvss epss 0.13

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6148.

  • CVE-2015-6155Dec 9, 2015
    risk 0.01cvss epss 0.17

    Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."

  • CVE-2015-6154Dec 9, 2015
    risk 0.01cvss epss 0.17

    Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than…

  • CVE-2015-6153Dec 9, 2015
    risk 0.01cvss epss 0.17

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140,…

  • CVE-2015-6146Dec 9, 2015
    risk 0.01cvss epss 0.13

    Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6145.

  • CVE-2015-6145Dec 9, 2015
    risk 0.01cvss epss 0.13

    Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6146.

  • CVE-2015-6144Dec 9, 2015
    risk 0.01cvss epss 0.13

    Microsoft Internet Explorer 8 through 11 and Microsoft Edge mishandle HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Browser XSS Filter Bypass Vulnerability."

  • CVE-2015-6140Dec 9, 2015
    risk 0.01cvss epss 0.17

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6142,…

  • CVE-2015-6139Dec 9, 2015
    risk 0.01cvss epss 0.15

    Microsoft Internet Explorer 11 and Microsoft Edge mishandle content types, which allows remote attackers to execute arbitrary web script in a privileged context via a crafted web site, aka "Microsoft Browser Elevation of Privilege Vulnerability."

  • CVE-2015-6138Dec 9, 2015
    risk 0.01cvss epss 0.12

    Microsoft Internet Explorer 8 through 11 mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Internet Explorer XSS Filter Bypass Vulnerability."

Page 264 of 314