VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2000-0770Oct 20, 2000
    risk 0.01cvss epss 0.15

    IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability.

  • CVE-2000-0768Oct 20, 2000
    risk 0.01cvss epss 0.10

    A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.

  • CVE-2000-0746Oct 20, 2000
    risk 0.01cvss epss 0.10

    Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client…

  • CVE-2000-0788Oct 20, 2000
    risk 0.01cvss epss 0.08

    The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.

  • CVE-2000-1079Aug 29, 2000
    risk 0.01cvss epss 0.16

    Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.

  • CVE-2000-0612Jun 29, 2000
    risk 0.01cvss epss 0.09

    Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table.

  • CVE-2000-0597Jun 27, 2000
    risk 0.01cvss epss 0.12

    Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka…

  • CVE-2000-0503Jun 6, 2000
    risk 0.01cvss epss 0.09

    The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.

  • CVE-2000-0544Jun 5, 2000
    risk 0.01cvss epss 0.18

    Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.

  • CVE-2000-0524Jun 5, 2000
    risk 0.01cvss epss 0.15

    Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.

  • CVE-2000-0404May 25, 2000
    risk 0.01cvss epss 0.18

    The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability.

  • CVE-2000-0403May 25, 2000
    risk 0.01cvss epss 0.18

    The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the "HostAnnouncement Flooding" or "HostAnnouncement Frame" vulnerability.

  • CVE-2000-0464May 17, 2000
    risk 0.01cvss epss 0.13

    Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability.

  • CVE-2000-0439May 11, 2000
    risk 0.01cvss epss 0.06

    Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability.

  • CVE-2000-0331Apr 20, 2000
    risk 0.01cvss epss 0.07

    Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.

  • CVE-2000-0266Apr 18, 2000
    risk 0.01cvss epss 0.16

    Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.

  • CVE-2000-0226Mar 20, 2000
    risk 0.01cvss epss 0.07

    IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the "Chunked Transfer Encoding Buffer Overflow Vulnerability."

  • CVE-2000-0228Mar 17, 2000
    risk 0.01cvss epss 0.14

    Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the "Malformed Media License Request" Vulnerability.

  • CVE-2000-0202Mar 8, 2000
    risk 0.01cvss epss 0.10

    Microsoft SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0 allow remote attackers to gain privileges via a malformed Select statement in an SQL query.

  • CVE-2000-0201Mar 1, 2000
    risk 0.01cvss epss 0.07

    The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking.

  • CVE-2000-0160Feb 21, 2000
    risk 0.01cvss epss 0.09

    The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.

  • CVE-2000-0161Feb 18, 2000
    risk 0.01cvss epss 0.10

    Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands.

  • CVE-2000-0162Feb 18, 2000
    risk 0.01cvss epss 0.08

    The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.

  • CVE-2000-0222Feb 15, 2000
    risk 0.01cvss epss 0.15

    The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs.

  • CVE-2000-0115Jan 21, 2000
    risk 0.01cvss epss 0.10

    IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page.

  • CVE-2000-0071Jan 11, 2000
    risk 0.01cvss epss 0.28

    IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.

  • CVE-2000-0085Jan 4, 2000
    risk 0.01cvss epss 0.15

    Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.

  • CVE-2000-0053Jan 4, 2000
    risk 0.01cvss epss 0.15

    Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.

  • CVE-2000-0082Jan 2, 2000
    risk 0.01cvss epss 0.15

    WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML.

  • CVE-1999-1094Dec 31, 1999
    risk 0.01cvss epss 0.18

    Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."

  • CVE-1999-1473Dec 31, 1999
    risk 0.01cvss epss 0.07

    When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue."

  • CVE-1999-1148Dec 31, 1999
    risk 0.01cvss epss 0.17

    FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.

  • CVE-1999-0815Dec 31, 1999
    risk 0.01cvss epss 0.18

    Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.

  • CVE-1999-1591Dec 31, 1999
    risk 0.01cvss epss 0.11

    Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via…

  • CVE-1999-1087Dec 31, 1999
    risk 0.01cvss epss 0.06

    Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by…

  • CVE-1999-1093Dec 31, 1999
    risk 0.01cvss epss 0.13

    Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.

  • CVE-1999-1132Dec 31, 1999
    risk 0.01cvss epss 0.18

    Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.

  • CVE-1999-1035Dec 31, 1999
    risk 0.01cvss epss 0.17

    IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.

  • CVE-1999-1043Dec 31, 1999
    risk 0.01cvss epss 0.13

    Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).

  • CVE-1999-1055Dec 31, 1999
    risk 0.01cvss epss 0.07

    Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."

  • CVE-1999-1472Dec 31, 1999
    risk 0.01cvss epss 0.17

    Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue.

  • CVE-1999-1474Dec 31, 1999
    risk 0.01cvss epss 0.09

    PowerPoint 95 and 97 allows remote attackers to cause an application to be run automatically without prompting the user, possibly through the slide show, when the document is opened in browsers such as Internet Explorer.

  • CVE-1999-1246Dec 31, 1999
    risk 0.01cvss epss 0.09

    Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.

  • CVE-1999-1451Dec 31, 1999
    risk 0.01cvss epss 0.18

    The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.

  • CVE-1999-1157Dec 31, 1999
    risk 0.01cvss epss 0.13

    Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.

  • CVE-2000-0024Dec 21, 1999
    risk 0.01cvss epss 0.12

    IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.

  • CVE-1999-0994Dec 16, 1999
    risk 0.01cvss epss 0.07

    Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.

  • CVE-1999-0993Dec 13, 1999
    risk 0.01cvss epss 0.07

    Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.

  • CVE-1999-0858Dec 2, 1999
    risk 0.01cvss epss 0.13

    Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.

  • CVE-1999-0387Nov 29, 1999
    risk 0.01cvss epss 0.08

    A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.

Page 287 of 314