Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 23522 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-0660 1 Microsoft 4 Windows 2000, Windows 2003 Server, Windows Nt and 1 more 2026-04-16 7.5 HIGH N/A
The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers to execute arbitrary code without user approval.
CVE-2001-1452 1 Microsoft 2 Windows 2000, Windows Nt 2026-04-16 5.0 MEDIUM 7.5 HIGH
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.
CVE-2003-1326 1 Microsoft 2 Ie, Internet Explorer 2026-04-16 7.5 HIGH N/A
Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."
CVE-1999-0777 1 Microsoft 2 Commercial Internet System, Internet Information Server 2026-04-16 7.5 HIGH N/A
IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.
CVE-2001-0663 1 Microsoft 2 Windows 2000, Windows Nt 2026-04-16 5.0 MEDIUM N/A
Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.
CVE-2006-1189 1 Microsoft 1 Internet Explorer 2026-04-16 10.0 HIGH N/A
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the "Double Byte Character Parsing Memory Corruption Vulnerability."
CVE-1999-1235 1 Microsoft 1 Internet Explorer 2026-04-16 4.6 MEDIUM N/A
Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.
CVE-2003-1448 1 Microsoft 1 Windows 2000 2026-04-16 7.8 HIGH N/A
Memory leak in the Windows 2000 kernel allows remote attackers to cause a denial of service (SMB request hang) via a NetBIOS continuation packet.
CVE-2002-0050 1 Microsoft 1 Commerce Server 2026-04-16 7.5 HIGH N/A
Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 allows remote attackers to execute arbitrary code via long authentication data.
CVE-1999-0876 1 Microsoft 2 Ie, Internet Explorer 2026-04-16 10.0 HIGH N/A
Buffer overflow in Internet Explorer 4.0 via EMBED tag.
CVE-2003-0768 1 Microsoft 1 Asp.net 2026-04-16 6.8 MEDIUM N/A
Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.
CVE-2006-1992 1 Microsoft 1 Internet Explorer 2026-04-16 2.6 LOW N/A
mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that this issue is non-exploitable.
CVE-2004-0869 1 Microsoft 1 Ie 2026-04-16 5.0 MEDIUM N/A
Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."
CVE-2006-4301 1 Microsoft 1 Ie 2026-04-16 5.0 MEDIUM N/A
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attribute in multiple DirectX Media Image DirectX Transforms ActiveX COM Objects from (a) dxtmsft.dll and (b) dxtmsft3.dll, including (1) DXImageTransform.Microsoft.MaskFilter.1, (2) DXImageTransform.Microsoft.Chroma.1, and (3) DX3DTransform.Microsoft.Shapes.1.
CVE-2000-0475 1 Microsoft 1 Windows 2000 2026-04-16 4.6 MEDIUM N/A
Windows 2000 allows a local user process to access another user's desktop within the same windows station, aka the "Desktop Separation" vulnerability.
CVE-2003-0604 1 Microsoft 1 Windows Media Player 2026-04-16 7.5 HIGH N/A
Windows Media Player (WMP) 7 and 8, as running on Internet Explorer and possibly other Microsoft products that process HTML, allows remote attackers to bypass zone restrictions and access or execute arbitrary files via an IFRAME tag pointing to an ASF file whose Content-location contains a File:// URL.
CVE-2004-1376 1 Microsoft 1 Internet Explorer 2026-04-16 5.0 MEDIUM N/A
Directory traversal vulnerability in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.
CVE-2006-3444 1 Microsoft 1 Windows 2000 2026-04-16 7.5 HIGH N/A
Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, probably a buffer overflow, allows local users to obtain privileges via unspecified vectors involving an "unchecked buffer."
CVE-2006-0029 1 Microsoft 2 Excel, Office 2026-04-16 5.1 MEDIUM N/A
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.
CVE-2006-1190 1 Microsoft 1 Internet Explorer 2026-04-16 10.0 HIGH N/A
Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.