VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2001-0721Dec 6, 2001
    risk 0.01cvss epss 0.17

    Universal Plug and Play (UPnP) in Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service (memory consumption or crash) via a malformed UPnP request.

  • CVE-2001-0726Dec 6, 2001
    risk 0.01cvss epss 0.16

    Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.

  • CVE-2001-0807Dec 6, 2001
    risk 0.01cvss epss 0.07

    Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file.

  • CVE-2001-0902Nov 20, 2001
    risk 0.01cvss epss 0.19

    Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters.

  • CVE-2001-0904Nov 20, 2001
    risk 0.01cvss epss 0.07

    Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgent) information that indicates that the patch has been installed, which could allow remote malicious web sites to more easily identify and exploit vulnerable clients.

  • CVE-2001-0724Nov 14, 2001
    risk 0.01cvss epss 0.12

    Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing…

  • CVE-2001-0723Nov 14, 2001
    risk 0.01cvss epss 0.11

    Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability."

  • CVE-2001-0665Oct 30, 2001
    risk 0.01cvss epss 0.12

    Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP Request Encoding…

  • CVE-2001-0718Oct 30, 2001
    risk 0.01cvss epss 0.11

    Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.

  • CVE-2001-0545Oct 30, 2001
    risk 0.01cvss epss 0.18

    IIS 4.0 with URL redirection enabled allows remote attackers to cause a denial of service (crash) via a malformed request that specifies a length that is different than the actual length.

  • CVE-2001-0509Sep 20, 2001
    risk 0.01cvss epss 0.17

    Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.

  • CVE-2001-0659Sep 20, 2001
    risk 0.01cvss epss 0.08

    Buffer overflow in IrDA driver providing infrared data exchange on Windows 2000 allows attackers who are physically close to the machine to cause a denial of service (reboot) via a malformed IrDA packet.

  • CVE-2001-0546Sep 20, 2001
    risk 0.01cvss epss 0.17

    Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.

  • CVE-2001-0541Sep 20, 2001
    risk 0.01cvss epss 0.16

    Buffer overflow in Microsoft Windows Media Player 7.1 and earlier allows remote attackers to execute arbitrary commands via a malformed Windows Media Station (.NSC) file.

  • CVE-2001-0658Sep 20, 2001
    risk 0.01cvss epss 0.14

    Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error…

  • CVE-2001-0999Sep 12, 2001
    risk 0.01cvss epss 0.12

    Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script.

  • CVE-2001-0018Jul 21, 2001
    risk 0.01cvss epss 0.18

    Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests.

  • CVE-2001-0345Jul 21, 2001
    risk 0.01cvss epss 0.07

    Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.

  • CVE-2001-0340Jul 21, 2001
    risk 0.01cvss epss 0.06

    An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.

  • CVE-2001-0347Jul 21, 2001
    risk 0.01cvss epss 0.14

    Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.

  • CVE-2001-0503Jul 21, 2001
    risk 0.01cvss epss 0.17

    Microsoft NetMeeting 3.01 with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service via a malformed string to the NetMeeting service port, aka a variant of the "NetMeeting Desktop Sharing" vulnerability.

  • CVE-2001-0238Jul 2, 2001
    risk 0.01cvss epss 0.15

    Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.

  • CVE-2001-0244Jun 27, 2001
    risk 0.01cvss epss 0.15

    Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.

  • CVE-2001-0339Jun 27, 2001
    risk 0.01cvss epss 0.15

    Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."

  • CVE-2001-0243Jun 27, 2001
    risk 0.01cvss epss 0.18

    Windows Media Player 7 and earlier stores Internet shortcuts in a user's Temporary Files folder with a fixed filename instead of in the Internet Explorer cache, which causes the HTML in those shortcuts to run in the Local Computer Zone instead of the Internet Zone, which allows…

  • CVE-2001-0237Jun 27, 2001
    risk 0.01cvss epss 0.18

    Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.

  • CVE-2001-0245Jun 27, 2001
    risk 0.01cvss epss 0.14

    Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.

  • CVE-2001-1450May 11, 2001
    risk 0.01cvss epss 0.07

    Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./".

  • CVE-2001-0154May 3, 2001
    risk 0.01cvss epss 0.11

    HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.

  • CVE-2001-0147May 3, 2001
    risk 0.01cvss epss 0.06

    Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records.

  • CVE-2001-0145May 3, 2001
    risk 0.01cvss epss 0.07

    Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.

  • CVE-2001-0153May 3, 2001
    risk 0.01cvss epss 0.12

    Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.

  • CVE-2001-0017Mar 12, 2001
    risk 0.01cvss epss 0.17

    Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability.

  • CVE-2001-0092Feb 16, 2001
    risk 0.01cvss epss 0.12

    A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.

  • CVE-2001-0045Feb 16, 2001
    risk 0.01cvss epss 0.08

    The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.

  • CVE-2001-0083Feb 12, 2001
    risk 0.01cvss epss 0.17

    Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the "Severed Windows Media Server…

  • CVE-2000-1090Feb 12, 2001
    risk 0.01cvss epss 0.17

    Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.

  • CVE-2001-0014Feb 12, 2001
    risk 0.01cvss epss 0.13

    Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.

  • CVE-2001-0003Feb 12, 2001
    risk 0.01cvss epss 0.07

    Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM…

  • CVE-2001-0096Feb 12, 2001
    risk 0.01cvss epss 0.20

    FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.

  • CVE-2000-1111Jan 9, 2001
    risk 0.01cvss epss 0.13

    Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input.

  • CVE-2000-1149Jan 9, 2001
    risk 0.01cvss epss 0.16

    Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the "Terminal Server Login Buffer Overflow" vulnerability.

  • CVE-2000-1227Dec 31, 2000
    risk 0.01cvss epss 0.13

    Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.

  • CVE-2000-0982Dec 19, 2000
    risk 0.01cvss epss 0.13

    Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability.

  • CVE-2000-0885Dec 19, 2000
    risk 0.01cvss epss 0.13

    Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing"…

  • CVE-2000-0817Dec 19, 2000
    risk 0.01cvss epss 0.15

    Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability.

  • CVE-2000-0980Dec 19, 2000
    risk 0.01cvss epss 0.13

    NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network.

  • CVE-2000-1003Dec 11, 2000
    risk 0.01cvss epss 0.13

    NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash.

  • CVE-2000-1006Dec 11, 2000
    risk 0.01cvss epss 0.15

    Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability.

  • CVE-2000-0849Nov 14, 2000
    risk 0.01cvss epss 0.15

    Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.

Page 286 of 314