VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-1999-0585Jul 1, 2000
    risk 0.00cvss epss 0.02

    A Windows NT administrator account has the default name of Administrator.

  • CVE-2000-0475Jun 15, 2000
    risk 0.00cvss epss 0.02

    Windows 2000 allows a local user process to access another user's desktop within the same windows station, aka the "Desktop Separation" vulnerability.

  • CVE-2000-0518Jun 5, 2000
    risk 0.00cvss epss 0.05

    Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities.

  • CVE-2000-0519Jun 5, 2000
    risk 0.00cvss epss 0.05

    Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities.

  • CVE-2000-0487Jun 1, 2000
    risk 0.00cvss epss 0.02

    The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability.

  • CVE-1999-0590Jun 1, 2000
    risk 0.00cvss epss 0.06

    A system does not present an appropriate legal message or warning to a user who is accessing it.

  • CVE-2000-0485May 30, 2000
    risk 0.00cvss epss 0.02

    Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability.

  • CVE-2000-0415May 12, 2000
    risk 0.00cvss epss 0.06

    Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.

  • CVE-2000-0416May 11, 2000
    risk 0.00cvss epss 0.06

    NTMail 5.x allows network users to bypass the NTMail proxy restrictions by redirecting their requests to NTMail's web configuration server.

  • CVE-2000-0420May 11, 2000
    risk 0.00cvss epss 0.01

    The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data.

  • CVE-2000-0311Apr 20, 2000
    risk 0.00cvss epss 0.01

    The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability.

  • CVE-2000-0259Apr 12, 2000
    risk 0.00cvss epss 0.01

    The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users.

  • CVE-1999-0701Apr 11, 2000
    risk 0.00cvss epss 0.02

    After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.

  • CVE-2000-0298Apr 7, 2000
    risk 0.00cvss epss 0.02

    The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories.

  • CVE-2000-0277Apr 3, 2000
    risk 0.00cvss epss 0.02

    Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.

  • CVE-2000-0199Mar 14, 2000
    risk 0.00cvss epss 0.01

    When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password.

  • CVE-2000-0216Feb 29, 2000
    risk 0.00cvss epss 0.05

    Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution…

  • CVE-2000-0197Feb 14, 2000
    risk 0.00cvss epss 0.02

    The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.

  • CVE-2000-0089Feb 4, 2000
    risk 0.00cvss epss 0.02

    The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.

  • CVE-1999-0595Jan 20, 2000
    risk 0.00cvss epss 0.02

    A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.

  • CVE-2000-0088Jan 20, 2000
    risk 0.00cvss epss 0.02

    Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability.

  • CVE-2000-0070Jan 12, 2000
    risk 0.00cvss epss 0.02

    NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC Port Request."

  • CVE-1999-0876Jan 4, 2000
    risk 0.00cvss epss 0.06

    Buffer overflow in Internet Explorer 4.0 via EMBED tag.

  • CVE-1999-1363Dec 31, 1999
    risk 0.00cvss epss 0.01

    Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool.

  • CVE-1999-1294Dec 31, 1999
    risk 0.00cvss epss 0.02

    Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission.

  • CVE-1999-1316Dec 31, 1999
    risk 0.00cvss epss 0.04

    Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.

  • CVE-1999-1317Dec 31, 1999
    risk 0.00cvss epss 0.02

    Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.

  • CVE-1999-1279Dec 31, 1999
    risk 0.00cvss epss 0.06

    An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.

  • CVE-1999-1358Dec 31, 1999
    risk 0.00cvss epss 0.01

    When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by…

  • CVE-1999-1359Dec 31, 1999
    risk 0.00cvss epss 0.04

    When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies.

  • CVE-1999-1360Dec 31, 1999
    risk 0.00cvss epss 0.01

    Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.

  • CVE-1999-1362Dec 31, 1999
    risk 0.00cvss epss 0.01

    Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters.

  • CVE-1999-1364Dec 31, 1999
    risk 0.00cvss epss 0.01

    Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.

  • CVE-1999-1452Dec 31, 1999
    risk 0.00cvss epss 0.06

    GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt.

  • CVE-1999-1455Dec 31, 1999
    risk 0.00cvss epss 0.04

    RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host.

  • CVE-1999-1259Dec 31, 1999
    risk 0.00cvss epss 0.03

    Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information.

  • CVE-1999-1104Dec 31, 1999
    risk 0.00cvss epss 0.01

    Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.

  • CVE-1999-1222Dec 31, 1999
    risk 0.00cvss epss 0.05

    Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.

  • CVE-1999-1233Dec 31, 1999
    risk 0.00cvss epss 0.05

    IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.

  • CVE-2000-0036Dec 22, 1999
    risk 0.00cvss epss 0.04

    Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.

  • CVE-1999-0824Nov 30, 1999
    risk 0.00cvss epss 0.01

    A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.

  • CVE-1999-0839Nov 29, 1999
    risk 0.00cvss epss 0.02

    Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.

  • CVE-1999-0987Nov 18, 1999
    risk 0.00cvss epss 0.05

    Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.

  • CVE-1999-0827Nov 1, 1999
    risk 0.00cvss epss 0.05

    By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.

  • CVE-1999-0354Nov 1, 1999
    risk 0.00cvss epss 0.05

    Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious…

  • CVE-1999-0794Oct 1, 1999
    risk 0.00cvss epss 0.01

    Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.

  • CVE-1999-0910Sep 10, 1999
    risk 0.00cvss epss 0.06

    Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.

  • CVE-1999-0861Aug 11, 1999
    risk 0.00cvss epss 0.03

    Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.

  • CVE-1999-0680Aug 9, 1999
    risk 0.00cvss epss 0.06

    Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.

  • CVE-2000-0323Jul 28, 1999
    risk 0.00cvss epss 0.06

    The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.