VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-1999-0728Jul 6, 1999
    risk 0.00cvss epss 0.06

    A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.

  • CVE-1999-1365Jun 28, 1999
    risk 0.00cvss epss 0.03

    Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a…

  • CVE-1999-0917May 27, 1999
    risk 0.00cvss epss 0.06

    The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.

  • CVE-1999-0229May 12, 1999
    risk 0.00cvss epss 0.06

    Denial of service in Windows NT IIS server using ..\..

  • CVE-1999-0717May 7, 1999
    risk 0.00cvss epss 0.06

    A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.

  • CVE-1999-1367May 6, 1999
    risk 0.00cvss epss 0.01

    Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users.

  • CVE-1999-1097May 4, 1999
    risk 0.00cvss epss 0.04

    Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.

  • CVE-1999-1370Mar 23, 1999
    risk 0.00cvss epss 0.01

    The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled…

  • CVE-1999-0419Mar 1, 1999
    risk 0.00cvss epss 0.01

    When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.

  • CVE-1999-0379Feb 22, 1999
    risk 0.00cvss epss 0.06

    Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.

  • CVE-1999-0407Feb 9, 1999
    risk 0.00cvss epss 0.05

    By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.

  • CVE-1999-0366Feb 8, 1999
    risk 0.00cvss epss 0.04

    In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.

  • CVE-1999-0119Jan 19, 1999
    risk 0.00cvss epss 0.06

    Windows NT 4.0 beta allows users to read and delete shares.

  • CVE-1999-0391Jan 5, 1999
    risk 0.00cvss epss 0.05

    The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.

  • CVE-1999-0593Jan 1, 1999
    risk 0.00cvss epss 0.02

    The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.

  • CVE-1999-0364Jan 1, 1999
    risk 0.00cvss epss 0.05

    Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.

  • CVE-1999-0579Jan 1, 1999
    risk 0.00cvss epss 0.06

    A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.

  • CVE-1999-0578Jan 1, 1999
    risk 0.00cvss epss 0.02

    A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.

  • CVE-1999-0384Jan 1, 1999
    risk 0.00cvss epss 0.01

    The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.

  • CVE-1999-0577Jan 1, 1999
    risk 0.00cvss epss 0.06

    A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.

  • CVE-1999-0465Jan 1, 1999
    risk 0.00cvss epss 0.03

    Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.

  • CVE-1999-0570Jan 1, 1999
    risk 0.00cvss epss 0.06

    Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.

  • CVE-1999-0665Jan 1, 1999
    risk 0.00cvss epss 0.02

    An application-critical Windows NT registry key has an inappropriate value.

  • CVE-1999-0592Jan 1, 1999
    risk 0.00cvss epss 0.02

    The Logon box of a Windows NT system displays the name of the last user who logged in.

  • CVE-1999-0560Jan 1, 1999
    risk 0.00cvss epss 0.06

    A system-critical Windows NT file or directory has inappropriate permissions.

  • CVE-1999-0549Jan 1, 1999
    risk 0.00cvss epss 0.02

    Windows NT automatically logs in an administrator upon rebooting.

  • CVE-1999-0611Jan 1, 1999
    risk 0.00cvss epss 0.02

    A system-critical Windows NT registry key has an inappropriate value.

  • CVE-1999-0226Jan 1, 1999
    risk 0.00cvss epss 0.06

    Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.

  • CVE-1999-1322Nov 12, 1998
    risk 0.00cvss epss 0.01

    The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.

  • CVE-1999-0505Oct 1, 1998
    risk 0.00cvss epss 0.02

    A Windows NT domain user or administrator account has a guessable password.

  • CVE-1999-0546Oct 1, 1998
    risk 0.00cvss epss 0.02

    The Windows NT guest account is enabled.

  • CVE-1999-0344Aug 1, 1998
    risk 0.00cvss epss 0.01

    NT users can gain debug-level access on a system process using the Sechole exploit.

  • CVE-1999-1556Jun 29, 1998
    risk 0.00cvss epss 0.02

    Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.

  • CVE-1999-1443Jun 2, 1998
    risk 0.00cvss epss 0.00

    Micah Software Full Armor Network Configurator and Zero Administration allow local users with physical access to bypass the desktop protection by (1) using and kill the process using the task manager, (2) booting the system from a separate disk, or (3)…

  • CVE-1999-0537Apr 1, 1998
    risk 0.00cvss epss 0.06

    A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.

  • CVE-1999-0258Feb 13, 1998
    risk 0.00cvss epss 0.06

    Bonk variation of teardrop IP fragmentation denial of service.

  • CVE-1999-0331Jan 1, 1998
    risk 0.00cvss epss 0.05

    Buffer overflow in Internet Explorer 4.0(1).

  • CVE-1999-0004Dec 16, 1997
    risk 0.00cvss epss 0.03

    MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.

  • CVE-1999-1446Aug 5, 1997
    risk 0.00cvss epss 0.02

    Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders…

  • CVE-1999-1217Jul 25, 1997
    risk 0.00cvss epss 0.02

    The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.

  • CVE-1999-0275Jun 10, 1997
    risk 0.00cvss epss 0.06

    Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.

  • CVE-1999-0227Jun 1, 1997
    risk 0.00cvss epss 0.05

    Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.

  • CVE-1999-0292Apr 1, 1997
    risk 0.00cvss epss 0.06

    Denial of service through Winpopup using large user names.

  • CVE-1999-1128Mar 1, 1997
    risk 0.00cvss epss 0.04

    Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user.

  • CVE-1999-0228Feb 7, 1997
    risk 0.00cvss epss 0.05

    Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.

  • CVE-1999-0274Jan 1, 1997
    risk 0.00cvss epss 0.06

    Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.

  • CVE-1999-0503Jan 1, 1997
    risk 0.00cvss epss 0.02

    A Windows NT local user or administrator account has a guessable password.

  • CVE-1999-0499Jan 1, 1997
    risk 0.00cvss epss 0.05

    NETBIOS share information may be published through SNMP registry keys in NT.

  • CVE-1999-0496Jan 1, 1997
    risk 0.00cvss epss 0.01

    A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.

  • CVE-1999-0179Jan 1, 1997
    risk 0.00cvss epss 0.06

    Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.

Page 313 of 314