Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 25612 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0261 1 Microsoft 1 Windows 2000 2026-06-16 2.1 LOW N/A
Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.
CVE-2001-0246 1 Microsoft 1 Internet Explorer 2026-06-16 5.0 MEDIUM N/A
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability.
CVE-2001-0245 1 Microsoft 2 Index Server, Indexing Service 2026-06-16 5.0 MEDIUM N/A
Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.
CVE-2001-0244 1 Microsoft 1 Index Server 2026-06-16 7.5 HIGH N/A
Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.
CVE-2001-0243 1 Microsoft 1 Windows Media Player 2026-06-16 5.0 MEDIUM N/A
Windows Media Player 7 and earlier stores Internet shortcuts in a user's Temporary Files folder with a fixed filename instead of in the Internet Explorer cache, which causes the HTML in those shortcuts to run in the Local Computer Zone instead of the Internet Zone, which allows remote attackers to read certain files.
CVE-2001-0242 1 Microsoft 1 Windows Media Player 2026-06-16 7.5 HIGH N/A
Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed in MS:MS00-090.
CVE-2001-0241 1 Microsoft 1 Windows 2000 2026-06-16 10.0 HIGH N/A
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.
CVE-2001-0240 1 Microsoft 1 Word 2026-06-16 4.6 MEDIUM N/A
Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.
CVE-2001-0239 1 Microsoft 1 Isa Server 2026-06-16 7.5 HIGH N/A
Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.
CVE-2001-0238 1 Microsoft 6 Windows 2000, Windows 95, Windows 98 and 3 more 2026-06-16 7.5 HIGH N/A
Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.
CVE-2001-0237 1 Microsoft 1 Windows 2000 2026-06-16 5.0 MEDIUM N/A
Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.
CVE-2001-0162 1 Microsoft 1 Windows Embedded Compact 2026-06-16 7.5 HIGH N/A
WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.
CVE-2001-0154 1 Microsoft 1 Internet Explorer 2026-06-16 7.5 HIGH N/A
HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.
CVE-2001-0153 1 Microsoft 2 Visual Basic, Visual Studio 2026-06-16 7.5 HIGH N/A
Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.
CVE-2001-0152 1 Microsoft 1 Plus 2026-06-16 2.1 LOW N/A
The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password information to a file, which allows local users to recover the passwords and read the compressed folders.
CVE-2001-0151 1 Microsoft 1 Internet Information Services 2026-06-16 5.0 MEDIUM N/A
IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.
CVE-2001-0150 1 Microsoft 1 Internet Explorer 2026-06-16 5.1 MEDIUM N/A
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.
CVE-2001-0149 1 Microsoft 1 Internet Explorer 2026-06-16 5.0 MEDIUM N/A
Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.
CVE-2001-0148 1 Microsoft 1 Windows Media Player 2026-06-16 7.5 HIGH N/A
The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.
CVE-2001-0147 1 Microsoft 1 Windows 2000 2026-06-16 10.0 HIGH N/A
Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records.