VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-1999-0898Nov 4, 1999
    risk 0.01cvss epss 0.07

    Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.

  • CVE-1999-1234Oct 26, 1999
    risk 0.01cvss epss 0.13

    LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.

  • CVE-1999-0766Oct 21, 1999
    risk 0.01cvss epss 0.07

    The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.

  • CVE-2000-0327Oct 21, 1999
    risk 0.01cvss epss 0.12

    Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability.

  • CVE-1999-0777Sep 23, 1999
    risk 0.01cvss epss 0.12

    IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.

  • CVE-1999-0909Sep 20, 1999
    risk 0.01cvss epss 0.12

    Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.

  • CVE-1999-0670Sep 1, 1999
    risk 0.01cvss epss 0.09

    Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.

  • CVE-1999-1052Aug 24, 1999
    risk 0.01cvss epss 0.14

    Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.

  • CVE-1999-0721Jul 20, 1999
    risk 0.01cvss epss 0.09

    Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.

  • CVE-1999-1537Jul 7, 1999
    risk 0.01cvss epss 0.09

    IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform…

  • CVE-1999-1478Jul 6, 1999
    risk 0.01cvss epss 0.18

    The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.

  • CVE-1999-0726Jun 30, 1999
    risk 0.01cvss epss 0.08

    An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.

  • CVE-1999-1164Jun 25, 1999
    risk 0.01cvss epss 0.13

    Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.

  • CVE-1999-0723Jun 23, 1999
    risk 0.01cvss epss 0.07

    The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.

  • CVE-1999-0802May 27, 1999
    risk 0.01cvss epss 0.10

    Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.

  • CVE-1999-0489May 17, 1999
    risk 0.01cvss epss 0.12

    MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.

  • CVE-1999-1241May 6, 1999
    risk 0.01cvss epss 0.14

    Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object.

  • CVE-1999-0488Apr 21, 1999
    risk 0.01cvss epss 0.12

    Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability.

  • CVE-1999-0490Apr 21, 1999
    risk 0.01cvss epss 0.10

    MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag.

  • CVE-1999-0444Apr 12, 1999
    risk 0.01cvss epss 0.16

    Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.

  • CVE-1999-0469Apr 1, 1999
    risk 0.01cvss epss 0.17

    Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.

  • CVE-2000-0153Mar 26, 1999
    risk 0.01cvss epss 0.14

    FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack.

  • CVE-1999-1397Mar 23, 1999
    risk 0.01cvss epss 0.12

    Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.

  • CVE-1999-1254Mar 8, 1999
    risk 0.01cvss epss 0.13

    Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.

  • CVE-1999-1201Feb 6, 1999
    risk 0.01cvss epss 0.14

    Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka…

  • CVE-1999-0349Jan 27, 1999
    risk 0.01cvss epss 0.18

    A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.

  • CVE-1999-0348Jan 27, 1999
    risk 0.01cvss epss 0.11

    IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.

  • CVE-1999-0357Jan 25, 1999
    risk 0.01cvss epss 0.16

    Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.

  • CVE-1999-1544Jan 24, 1999
    risk 0.01cvss epss 0.14

    Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.

  • CVE-1999-0561Jan 1, 1999
    risk 0.01cvss epss 0.08

    IIS has the #exec function enabled for Server Side Include (SSI) files.

  • CVE-1999-0581Jan 1, 1999
    risk 0.01cvss epss 0.07

    The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.

  • CVE-1999-0285Jan 1, 1999
    risk 0.01cvss epss 0.07

    Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.

  • CVE-1999-0332Dec 1, 1998
    risk 0.01cvss epss 0.13

    Buffer overflow in NetMeeting allows denial of service and remote command execution.

  • CVE-1999-0385Dec 1, 1998
    risk 0.01cvss epss 0.18

    The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.

  • CVE-1999-1291Oct 5, 1998
    risk 0.01cvss epss 0.13

    TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to…

  • CVE-1999-0870Oct 1, 1998
    risk 0.01cvss epss 0.13

    Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.

  • CVE-1999-0969Sep 29, 1998
    risk 0.01cvss epss 0.13

    The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.

  • CVE-1999-0871Sep 4, 1998
    risk 0.01cvss epss 0.12

    Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.

  • CVE-1999-1447Jul 28, 1998
    risk 0.01cvss epss 0.13

    Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.

  • CVE-1999-0007Jun 26, 1998
    risk 0.01cvss epss 0.08

    Information from SSL-encrypted sessions via PKCS #1.

  • CVE-1999-1361May 9, 1998
    risk 0.01cvss epss 0.09

    Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages.

  • CVE-1999-0225Feb 14, 1998
    risk 0.01cvss epss 0.19

    Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.

  • CVE-1999-0104Dec 16, 1997
    risk 0.01cvss epss 0.09

    A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.

  • CVE-1999-0967Nov 1, 1997
    risk 0.01cvss epss 0.07

    Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.

  • CVE-1999-1463Jul 10, 1997
    risk 0.01cvss epss 0.16

    Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.

  • CVE-1999-0031Jul 8, 1997
    risk 0.01cvss epss 0.18

    JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.

  • CVE-1999-0074Jul 1, 1997
    risk 0.01cvss epss 0.08

    Listening TCP ports are sequentially allocated, allowing spoofing attacks.

  • CVE-1999-0280Apr 1, 1997
    risk 0.01cvss epss 0.15

    Remote command execution in Microsoft Internet Explorer using .lnk and .url files.

  • CVE-1999-0253Jan 1, 1997
    risk 0.01cvss epss 0.08

    IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.

  • CVE-1999-0249Jan 1, 1997
    risk 0.01cvss epss 0.07

    Windows NT RSHSVC program allows remote users to execute arbitrary commands.

Page 288 of 314