Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0728 | 0.00 | — | 0.06 | Jul 6, 1999 | A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them. | |||
| CVE-1999-1365 | 0.00 | — | 0.03 | Jun 28, 1999 | Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a… | |||
| CVE-1999-0917 | 0.00 | — | 0.06 | May 27, 1999 | The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files. | |||
| CVE-1999-0229 | 0.00 | — | 0.06 | May 12, 1999 | Denial of service in Windows NT IIS server using ..\.. | |||
| CVE-1999-0717 | 0.00 | — | 0.06 | May 7, 1999 | A remote attacker can disable the virus warning mechanism in Microsoft Excel 97. | |||
| CVE-1999-1367 | 0.00 | — | 0.01 | May 6, 1999 | Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users. | |||
| CVE-1999-1097 | 0.00 | — | 0.04 | May 4, 1999 | Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty. | |||
| CVE-1999-1370 | 0.00 | — | 0.01 | Mar 23, 1999 | The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled… | |||
| CVE-1999-0419 | 0.00 | — | 0.01 | Mar 1, 1999 | When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service. | |||
| CVE-1999-0379 | 0.00 | — | 0.06 | Feb 22, 1999 | Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting. | |||
| CVE-1999-0407 | 0.00 | — | 0.05 | Feb 9, 1999 | By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. | |||
| CVE-1999-0366 | 0.00 | — | 0.04 | Feb 8, 1999 | In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. | |||
| CVE-1999-0119 | 0.00 | — | 0.06 | Jan 19, 1999 | Windows NT 4.0 beta allows users to read and delete shares. | |||
| CVE-1999-0391 | 0.00 | — | 0.05 | Jan 5, 1999 | The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. | |||
| CVE-1999-0593 | 0.00 | — | 0.02 | Jan 1, 1999 | The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. | |||
| CVE-1999-0364 | 0.00 | — | 0.05 | Jan 1, 1999 | Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data. | |||
| CVE-1999-0579 | 0.00 | — | 0.06 | Jan 1, 1999 | A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. | |||
| CVE-1999-0578 | 0.00 | — | 0.02 | Jan 1, 1999 | A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. | |||
| CVE-1999-0384 | 0.00 | — | 0.01 | Jan 1, 1999 | The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content. | |||
| CVE-1999-0577 | 0.00 | — | 0.06 | Jan 1, 1999 | A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. | |||
| CVE-1999-0465 | 0.00 | — | 0.03 | Jan 1, 1999 | Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter. | |||
| CVE-1999-0570 | 0.00 | — | 0.06 | Jan 1, 1999 | Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. | |||
| CVE-1999-0665 | 0.00 | — | 0.02 | Jan 1, 1999 | An application-critical Windows NT registry key has an inappropriate value. | |||
| CVE-1999-0592 | 0.00 | — | 0.02 | Jan 1, 1999 | The Logon box of a Windows NT system displays the name of the last user who logged in. | |||
| CVE-1999-0560 | 0.00 | — | 0.06 | Jan 1, 1999 | A system-critical Windows NT file or directory has inappropriate permissions. | |||
| CVE-1999-0549 | 0.00 | — | 0.02 | Jan 1, 1999 | Windows NT automatically logs in an administrator upon rebooting. | |||
| CVE-1999-0611 | 0.00 | — | 0.02 | Jan 1, 1999 | A system-critical Windows NT registry key has an inappropriate value. | |||
| CVE-1999-0226 | 0.00 | — | 0.06 | Jan 1, 1999 | Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service. | |||
| CVE-1999-1322 | 0.00 | — | 0.01 | Nov 12, 1998 | The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext. | |||
| CVE-1999-0505 | 0.00 | — | 0.02 | Oct 1, 1998 | A Windows NT domain user or administrator account has a guessable password. | |||
| CVE-1999-0546 | 0.00 | — | 0.02 | Oct 1, 1998 | The Windows NT guest account is enabled. | |||
| CVE-1999-0344 | 0.00 | — | 0.01 | Aug 1, 1998 | NT users can gain debug-level access on a system process using the Sechole exploit. | |||
| CVE-1999-1556 | 0.00 | — | 0.02 | Jun 29, 1998 | Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value. | |||
| CVE-1999-1443 | 0.00 | — | 0.00 | Jun 2, 1998 | Micah Software Full Armor Network Configurator and Zero Administration allow local users with physical access to bypass the desktop protection by (1) using and kill the process using the task manager, (2) booting the system from a separate disk, or (3)… | |||
| CVE-1999-0537 | 0.00 | — | 0.06 | Apr 1, 1998 | A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc. | |||
| CVE-1999-0258 | 0.00 | — | 0.06 | Feb 13, 1998 | Bonk variation of teardrop IP fragmentation denial of service. | |||
| CVE-1999-0331 | 0.00 | — | 0.05 | Jan 1, 1998 | Buffer overflow in Internet Explorer 4.0(1). | |||
| CVE-1999-0004 | 0.00 | — | 0.03 | Dec 16, 1997 | MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook. | |||
| CVE-1999-1446 | 0.00 | — | 0.02 | Aug 5, 1997 | Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders… | |||
| CVE-1999-1217 | 0.00 | — | 0.02 | Jul 25, 1997 | The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories. | |||
| CVE-1999-0275 | 0.00 | — | 0.06 | Jun 10, 1997 | Denial of service in Windows NT DNS servers by flooding port 53 with too many characters. | |||
| CVE-1999-0227 | 0.00 | — | 0.05 | Jun 1, 1997 | Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service. | |||
| CVE-1999-0292 | 0.00 | — | 0.06 | Apr 1, 1997 | Denial of service through Winpopup using large user names. | |||
| CVE-1999-1128 | 0.00 | — | 0.04 | Mar 1, 1997 | Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user. | |||
| CVE-1999-0228 | 0.00 | — | 0.05 | Feb 7, 1997 | Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT. | |||
| CVE-1999-0274 | 0.00 | — | 0.06 | Jan 1, 1997 | Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made. | |||
| CVE-1999-0503 | 0.00 | — | 0.02 | Jan 1, 1997 | A Windows NT local user or administrator account has a guessable password. | |||
| CVE-1999-0499 | 0.00 | — | 0.05 | Jan 1, 1997 | NETBIOS share information may be published through SNMP registry keys in NT. | |||
| CVE-1999-0496 | 0.00 | — | 0.01 | Jan 1, 1997 | A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin. | |||
| CVE-1999-0179 | 0.00 | — | 0.06 | Jan 1, 1997 | Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share. |
- CVE-1999-0728Jul 6, 1999risk 0.00cvss —epss 0.06
A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.
- CVE-1999-1365Jun 28, 1999risk 0.00cvss —epss 0.03
Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a…
- CVE-1999-0917May 27, 1999risk 0.00cvss —epss 0.06
The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.
- CVE-1999-0229May 12, 1999risk 0.00cvss —epss 0.06
Denial of service in Windows NT IIS server using ..\..
- CVE-1999-0717May 7, 1999risk 0.00cvss —epss 0.06
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
- CVE-1999-1367May 6, 1999risk 0.00cvss —epss 0.01
Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users.
- CVE-1999-1097May 4, 1999risk 0.00cvss —epss 0.04
Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.
- CVE-1999-1370Mar 23, 1999risk 0.00cvss —epss 0.01
The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled…
- CVE-1999-0419Mar 1, 1999risk 0.00cvss —epss 0.01
When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.
- CVE-1999-0379Feb 22, 1999risk 0.00cvss —epss 0.06
Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.
- CVE-1999-0407Feb 9, 1999risk 0.00cvss —epss 0.05
By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.
- CVE-1999-0366Feb 8, 1999risk 0.00cvss —epss 0.04
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.
- CVE-1999-0119Jan 19, 1999risk 0.00cvss —epss 0.06
Windows NT 4.0 beta allows users to read and delete shares.
- CVE-1999-0391Jan 5, 1999risk 0.00cvss —epss 0.05
The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.
- CVE-1999-0593Jan 1, 1999risk 0.00cvss —epss 0.02
The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.
- CVE-1999-0364Jan 1, 1999risk 0.00cvss —epss 0.05
Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
- CVE-1999-0579Jan 1, 1999risk 0.00cvss —epss 0.06
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
- CVE-1999-0578Jan 1, 1999risk 0.00cvss —epss 0.02
A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.
- CVE-1999-0384Jan 1, 1999risk 0.00cvss —epss 0.01
The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.
- CVE-1999-0577Jan 1, 1999risk 0.00cvss —epss 0.06
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
- CVE-1999-0465Jan 1, 1999risk 0.00cvss —epss 0.03
Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.
- CVE-1999-0570Jan 1, 1999risk 0.00cvss —epss 0.06
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.
- CVE-1999-0665Jan 1, 1999risk 0.00cvss —epss 0.02
An application-critical Windows NT registry key has an inappropriate value.
- CVE-1999-0592Jan 1, 1999risk 0.00cvss —epss 0.02
The Logon box of a Windows NT system displays the name of the last user who logged in.
- CVE-1999-0560Jan 1, 1999risk 0.00cvss —epss 0.06
A system-critical Windows NT file or directory has inappropriate permissions.
- CVE-1999-0549Jan 1, 1999risk 0.00cvss —epss 0.02
Windows NT automatically logs in an administrator upon rebooting.
- CVE-1999-0611Jan 1, 1999risk 0.00cvss —epss 0.02
A system-critical Windows NT registry key has an inappropriate value.
- CVE-1999-0226Jan 1, 1999risk 0.00cvss —epss 0.06
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
- CVE-1999-1322Nov 12, 1998risk 0.00cvss —epss 0.01
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.
- CVE-1999-0505Oct 1, 1998risk 0.00cvss —epss 0.02
A Windows NT domain user or administrator account has a guessable password.
- CVE-1999-0546Oct 1, 1998risk 0.00cvss —epss 0.02
The Windows NT guest account is enabled.
- CVE-1999-0344Aug 1, 1998risk 0.00cvss —epss 0.01
NT users can gain debug-level access on a system process using the Sechole exploit.
- CVE-1999-1556Jun 29, 1998risk 0.00cvss —epss 0.02
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.
- CVE-1999-1443Jun 2, 1998risk 0.00cvss —epss 0.00
Micah Software Full Armor Network Configurator and Zero Administration allow local users with physical access to bypass the desktop protection by (1) using and kill the process using the task manager, (2) booting the system from a separate disk, or (3)…
- CVE-1999-0537Apr 1, 1998risk 0.00cvss —epss 0.06
A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.
- CVE-1999-0258Feb 13, 1998risk 0.00cvss —epss 0.06
Bonk variation of teardrop IP fragmentation denial of service.
- CVE-1999-0331Jan 1, 1998risk 0.00cvss —epss 0.05
Buffer overflow in Internet Explorer 4.0(1).
- CVE-1999-0004Dec 16, 1997risk 0.00cvss —epss 0.03
MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.
- CVE-1999-1446Aug 5, 1997risk 0.00cvss —epss 0.02
Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders…
- CVE-1999-1217Jul 25, 1997risk 0.00cvss —epss 0.02
The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.
- CVE-1999-0275Jun 10, 1997risk 0.00cvss —epss 0.06
Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.
- CVE-1999-0227Jun 1, 1997risk 0.00cvss —epss 0.05
Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.
- CVE-1999-0292Apr 1, 1997risk 0.00cvss —epss 0.06
Denial of service through Winpopup using large user names.
- CVE-1999-1128Mar 1, 1997risk 0.00cvss —epss 0.04
Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user.
- CVE-1999-0228Feb 7, 1997risk 0.00cvss —epss 0.05
Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.
- CVE-1999-0274Jan 1, 1997risk 0.00cvss —epss 0.06
Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.
- CVE-1999-0503Jan 1, 1997risk 0.00cvss —epss 0.02
A Windows NT local user or administrator account has a guessable password.
- CVE-1999-0499Jan 1, 1997risk 0.00cvss —epss 0.05
NETBIOS share information may be published through SNMP registry keys in NT.
- CVE-1999-0496Jan 1, 1997risk 0.00cvss —epss 0.01
A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.
- CVE-1999-0179Jan 1, 1997risk 0.00cvss —epss 0.06
Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.
Page 313 of 314