Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0898 | 0.01 | — | 0.07 | Nov 4, 1999 | Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request. | |||
| CVE-1999-1234 | 0.01 | — | 0.13 | Oct 26, 1999 | LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo. | |||
| CVE-1999-0766 | 0.01 | — | 0.07 | Oct 21, 1999 | The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment. | |||
| CVE-2000-0327 | 0.01 | — | 0.12 | Oct 21, 1999 | Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability. | |||
| CVE-1999-0777 | 0.01 | — | 0.12 | Sep 23, 1999 | IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions. | |||
| CVE-1999-0909 | 0.01 | — | 0.12 | Sep 20, 1999 | Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability. | |||
| CVE-1999-0670 | 0.01 | — | 0.09 | Sep 1, 1999 | Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands. | |||
| CVE-1999-1052 | 0.01 | — | 0.14 | Aug 24, 1999 | Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users. | |||
| CVE-1999-0721 | 0.01 | — | 0.09 | Jul 20, 1999 | Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request. | |||
| CVE-1999-1537 | 0.01 | — | 0.09 | Jul 7, 1999 | IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform… | |||
| CVE-1999-1478 | 0.01 | — | 0.18 | Jul 6, 1999 | The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character. | |||
| CVE-1999-0726 | 0.01 | — | 0.08 | Jun 30, 1999 | An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header. | |||
| CVE-1999-1164 | 0.01 | — | 0.13 | Jun 25, 1999 | Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang. | |||
| CVE-1999-0723 | 0.01 | — | 0.07 | Jun 23, 1999 | The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input. | |||
| CVE-1999-0802 | 0.01 | — | 0.10 | May 27, 1999 | Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon. | |||
| CVE-1999-0489 | 0.01 | — | 0.12 | May 17, 1999 | MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013. | |||
| CVE-1999-1241 | 0.01 | — | 0.14 | May 6, 1999 | Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object. | |||
| CVE-1999-0488 | 0.01 | — | 0.12 | Apr 21, 1999 | Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability. | |||
| CVE-1999-0490 | 0.01 | — | 0.10 | Apr 21, 1999 | MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag. | |||
| CVE-1999-0444 | 0.01 | — | 0.16 | Apr 12, 1999 | Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files. | |||
| CVE-1999-0469 | 0.01 | — | 0.17 | Apr 1, 1999 | Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client. | |||
| CVE-2000-0153 | 0.01 | — | 0.14 | Mar 26, 1999 | FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack. | |||
| CVE-1999-1397 | 0.01 | — | 0.12 | Mar 23, 1999 | Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed. | |||
| CVE-1999-1254 | 0.01 | — | 0.13 | Mar 8, 1999 | Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables. | |||
| CVE-1999-1201 | 0.01 | — | 0.14 | Feb 6, 1999 | Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka… | |||
| CVE-1999-0349 | 0.01 | — | 0.18 | Jan 27, 1999 | A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. | |||
| CVE-1999-0348 | 0.01 | — | 0.11 | Jan 27, 1999 | IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory. | |||
| CVE-1999-0357 | 0.01 | — | 0.16 | Jan 25, 1999 | Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets. | |||
| CVE-1999-1544 | 0.01 | — | 0.14 | Jan 24, 1999 | Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command. | |||
| CVE-1999-0561 | 0.01 | — | 0.08 | Jan 1, 1999 | IIS has the #exec function enabled for Server Side Include (SSI) files. | |||
| CVE-1999-0581 | 0.01 | — | 0.07 | Jan 1, 1999 | The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. | |||
| CVE-1999-0285 | 0.01 | — | 0.07 | Jan 1, 1999 | Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection. | |||
| CVE-1999-0332 | 0.01 | — | 0.13 | Dec 1, 1998 | Buffer overflow in NetMeeting allows denial of service and remote command execution. | |||
| CVE-1999-0385 | 0.01 | — | 0.18 | Dec 1, 1998 | The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. | |||
| CVE-1999-1291 | 0.01 | — | 0.13 | Oct 5, 1998 | TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to… | |||
| CVE-1999-0870 | 0.01 | — | 0.13 | Oct 1, 1998 | Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste. | |||
| CVE-1999-0969 | 0.01 | — | 0.13 | Sep 29, 1998 | The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork. | |||
| CVE-1999-0871 | 0.01 | — | 0.12 | Sep 4, 1998 | Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability. | |||
| CVE-1999-1447 | 0.01 | — | 0.13 | Jul 28, 1998 | Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag. | |||
| CVE-1999-0007 | 0.01 | — | 0.08 | Jun 26, 1998 | Information from SSL-encrypted sessions via PKCS #1. | |||
| CVE-1999-1361 | 0.01 | — | 0.09 | May 9, 1998 | Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages. | |||
| CVE-1999-0225 | 0.01 | — | 0.19 | Feb 14, 1998 | Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size. | |||
| CVE-1999-0104 | 0.01 | — | 0.09 | Dec 16, 1997 | A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2. | |||
| CVE-1999-0967 | 0.01 | — | 0.07 | Nov 1, 1997 | Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol. | |||
| CVE-1999-1463 | 0.01 | — | 0.16 | Jul 10, 1997 | Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session. | |||
| CVE-1999-0031 | 0.01 | — | 0.18 | Jul 8, 1997 | JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability. | |||
| CVE-1999-0074 | 0.01 | — | 0.08 | Jul 1, 1997 | Listening TCP ports are sequentially allocated, allowing spoofing attacks. | |||
| CVE-1999-0280 | 0.01 | — | 0.15 | Apr 1, 1997 | Remote command execution in Microsoft Internet Explorer using .lnk and .url files. | |||
| CVE-1999-0253 | 0.01 | — | 0.08 | Jan 1, 1997 | IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. | |||
| CVE-1999-0249 | 0.01 | — | 0.07 | Jan 1, 1997 | Windows NT RSHSVC program allows remote users to execute arbitrary commands. |
- CVE-1999-0898Nov 4, 1999risk 0.01cvss —epss 0.07
Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.
- CVE-1999-1234Oct 26, 1999risk 0.01cvss —epss 0.13
LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.
- CVE-1999-0766Oct 21, 1999risk 0.01cvss —epss 0.07
The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.
- CVE-2000-0327Oct 21, 1999risk 0.01cvss —epss 0.12
Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability.
- CVE-1999-0777Sep 23, 1999risk 0.01cvss —epss 0.12
IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.
- CVE-1999-0909Sep 20, 1999risk 0.01cvss —epss 0.12
Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.
- CVE-1999-0670Sep 1, 1999risk 0.01cvss —epss 0.09
Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.
- CVE-1999-1052Aug 24, 1999risk 0.01cvss —epss 0.14
Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.
- CVE-1999-0721Jul 20, 1999risk 0.01cvss —epss 0.09
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
- CVE-1999-1537Jul 7, 1999risk 0.01cvss —epss 0.09
IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform…
- CVE-1999-1478Jul 6, 1999risk 0.01cvss —epss 0.18
The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.
- CVE-1999-0726Jun 30, 1999risk 0.01cvss —epss 0.08
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
- CVE-1999-1164Jun 25, 1999risk 0.01cvss —epss 0.13
Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.
- CVE-1999-0723Jun 23, 1999risk 0.01cvss —epss 0.07
The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.
- CVE-1999-0802May 27, 1999risk 0.01cvss —epss 0.10
Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.
- CVE-1999-0489May 17, 1999risk 0.01cvss —epss 0.12
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.
- CVE-1999-1241May 6, 1999risk 0.01cvss —epss 0.14
Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object.
- CVE-1999-0488Apr 21, 1999risk 0.01cvss —epss 0.12
Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability.
- CVE-1999-0490Apr 21, 1999risk 0.01cvss —epss 0.10
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag.
- CVE-1999-0444Apr 12, 1999risk 0.01cvss —epss 0.16
Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.
- CVE-1999-0469Apr 1, 1999risk 0.01cvss —epss 0.17
Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.
- CVE-2000-0153Mar 26, 1999risk 0.01cvss —epss 0.14
FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack.
- CVE-1999-1397Mar 23, 1999risk 0.01cvss —epss 0.12
Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.
- CVE-1999-1254Mar 8, 1999risk 0.01cvss —epss 0.13
Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.
- CVE-1999-1201Feb 6, 1999risk 0.01cvss —epss 0.14
Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka…
- CVE-1999-0349Jan 27, 1999risk 0.01cvss —epss 0.18
A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.
- CVE-1999-0348Jan 27, 1999risk 0.01cvss —epss 0.11
IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.
- CVE-1999-0357Jan 25, 1999risk 0.01cvss —epss 0.16
Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.
- CVE-1999-1544Jan 24, 1999risk 0.01cvss —epss 0.14
Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.
- CVE-1999-0561Jan 1, 1999risk 0.01cvss —epss 0.08
IIS has the #exec function enabled for Server Side Include (SSI) files.
- CVE-1999-0581Jan 1, 1999risk 0.01cvss —epss 0.07
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.
- CVE-1999-0285Jan 1, 1999risk 0.01cvss —epss 0.07
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
- CVE-1999-0332Dec 1, 1998risk 0.01cvss —epss 0.13
Buffer overflow in NetMeeting allows denial of service and remote command execution.
- CVE-1999-0385Dec 1, 1998risk 0.01cvss —epss 0.18
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.
- CVE-1999-1291Oct 5, 1998risk 0.01cvss —epss 0.13
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to…
- CVE-1999-0870Oct 1, 1998risk 0.01cvss —epss 0.13
Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.
- CVE-1999-0969Sep 29, 1998risk 0.01cvss —epss 0.13
The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.
- CVE-1999-0871Sep 4, 1998risk 0.01cvss —epss 0.12
Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.
- CVE-1999-1447Jul 28, 1998risk 0.01cvss —epss 0.13
Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.
- CVE-1999-0007Jun 26, 1998risk 0.01cvss —epss 0.08
Information from SSL-encrypted sessions via PKCS #1.
- CVE-1999-1361May 9, 1998risk 0.01cvss —epss 0.09
Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages.
- CVE-1999-0225Feb 14, 1998risk 0.01cvss —epss 0.19
Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.
- CVE-1999-0104Dec 16, 1997risk 0.01cvss —epss 0.09
A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.
- CVE-1999-0967Nov 1, 1997risk 0.01cvss —epss 0.07
Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.
- CVE-1999-1463Jul 10, 1997risk 0.01cvss —epss 0.16
Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.
- CVE-1999-0031Jul 8, 1997risk 0.01cvss —epss 0.18
JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.
- CVE-1999-0074Jul 1, 1997risk 0.01cvss —epss 0.08
Listening TCP ports are sequentially allocated, allowing spoofing attacks.
- CVE-1999-0280Apr 1, 1997risk 0.01cvss —epss 0.15
Remote command execution in Microsoft Internet Explorer using .lnk and .url files.
- CVE-1999-0253Jan 1, 1997risk 0.01cvss —epss 0.08
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.
- CVE-1999-0249Jan 1, 1997risk 0.01cvss —epss 0.07
Windows NT RSHSVC program allows remote users to execute arbitrary commands.
Page 288 of 314