Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 21870 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-1212 1 Microsoft 7 Windows 2000, Windows 2000 Terminal Services, Windows 2003 Server and 4 more 2025-04-03 7.5 HIGH N/A
Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.
CVE-2002-0617 1 Microsoft 2 Excel, Office 2025-04-03 5.1 MEDIUM N/A
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook Macro Bypass."
CVE-2001-0246 1 Microsoft 1 Internet Explorer 2025-04-03 5.0 MEDIUM N/A
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability.
CVE-2002-0624 1 Microsoft 2 Msde, Sql Server 2025-04-03 7.5 HIGH N/A
Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."
CVE-2006-4732 1 Microsoft 1 Visual Basic 2025-04-03 10.0 HIGH N/A
Unspecified vulnerability in Microsoft Visual Basic (VB) 6 has an unknown impact ("overflow") via a project that contains a certain Click event procedure, as demonstrated using the msgbox function and the VB.Label object.
CVE-2002-1705 1 Microsoft 1 Internet Explorer 2025-04-03 5.0 MEDIUM N/A
Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight.
CVE-2001-1450 1 Microsoft 1 Internet Explorer 2025-04-03 2.6 LOW N/A
Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./".
CVE-2001-0999 1 Microsoft 1 Outlook Express 2025-04-03 7.5 HIGH N/A
Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script.
CVE-2005-4679 1 Microsoft 1 Ie 2025-04-03 5.0 MEDIUM N/A
Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to spoof the URL in the status bar via the title in an image in a link to a trusted site within a form to the malicious site.
CVE-1999-0191 1 Microsoft 1 Internet Information Server 2025-04-03 6.4 MEDIUM N/A
IIS newdsn.exe CGI script allows remote users to overwrite files.
CVE-1999-0595 1 Microsoft 2 Windows 2000, Windows Nt 2025-04-03 2.1 LOW N/A
A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.
CVE-1999-1157 1 Microsoft 1 Windows Nt 2025-04-03 5.0 MEDIUM N/A
Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.
CVE-2006-0143 1 Microsoft 6 Windows 2000, Windows 2003 Server, Windows 98 and 3 more 2025-04-03 7.5 HIGH N/A
Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.
CVE-2002-1716 1 Microsoft 1 Office 2025-04-03 5.0 MEDIUM N/A
The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote attackers to create arbitrary files using the SaveAs capability.
CVE-2001-0015 1 Microsoft 1 Windows 2000 2025-04-03 7.2 HIGH N/A
Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process.
CVE-2004-2643 1 Microsoft 1 Cabarc 2025-04-03 3.7 LOW N/A
Directory traversal vulnerability in Microsoft cabarc allows remote attackers to overwrite files via "../" sequences in file names in a CAB archive.
CVE-1999-1451 1 Microsoft 2 Internet Information Server, Site Server 2025-04-03 5.0 MEDIUM N/A
The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.
CVE-2001-0541 1 Microsoft 1 Windows Media Player 2025-04-03 7.5 HIGH N/A
Buffer overflow in Microsoft Windows Media Player 7.1 and earlier allows remote attackers to execute arbitrary commands via a malformed Windows Media Station (.NSC) file.
CVE-2001-0162 1 Microsoft 1 Windows Embedded Compact 2025-04-03 7.5 HIGH N/A
WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.
CVE-1999-0292 1 Microsoft 1 Windows Nt 2025-04-03 5.0 MEDIUM N/A
Denial of service through Winpopup using large user names.