Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 25528 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0376 1 Microsoft 1 Windows Nt 2026-06-16 4.6 MEDIUM N/A
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.
CVE-1999-0372 1 Microsoft 3 Backoffice, Windows 2000, Windows Nt 2026-06-16 2.1 LOW N/A
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
CVE-1999-0366 1 Microsoft 1 Windows Nt 2026-06-16 7.5 HIGH N/A
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.
CVE-1999-0364 2 Fms Inc., Microsoft 2 Total Vb Sourcebook, Access 2026-06-16 10.0 HIGH N/A
Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
CVE-1999-0360 1 Microsoft 1 Site Server 2026-06-16 7.2 HIGH N/A
MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.
CVE-1999-0357 1 Microsoft 1 Windows 98 2026-06-16 5.0 MEDIUM N/A
Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.
CVE-1999-0354 1 Microsoft 2 Internet Explorer, Word 2026-06-16 7.5 HIGH N/A
Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.
CVE-1999-0349 1 Microsoft 1 Internet Information Server 2026-06-16 7.5 HIGH N/A
A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.
CVE-1999-0348 1 Microsoft 1 Internet Information Server 2026-06-16 5.0 MEDIUM N/A
IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.
CVE-1999-0344 1 Microsoft 1 Windows Nt 2026-06-16 7.2 HIGH N/A
NT users can gain debug-level access on a system process using the Sechole exploit.
CVE-1999-0332 1 Microsoft 1 Netmeeting 2026-06-16 7.5 HIGH N/A
Buffer overflow in NetMeeting allows denial of service and remote command execution.
CVE-1999-0331 1 Microsoft 1 Internet Explorer 2026-06-16 7.5 HIGH N/A
Buffer overflow in Internet Explorer 4.0(1).
CVE-1999-0294 1 Microsoft 1 Wins 2026-06-16 5.0 MEDIUM N/A
All records in a WINS database can be deleted through SNMP for a denial of service.
CVE-1999-0292 1 Microsoft 1 Windows Nt 2026-06-16 5.0 MEDIUM N/A
Denial of service through Winpopup using large user names.
CVE-1999-0289 2 Apache, Microsoft 2 Http Server, Windows 2026-06-16 5.0 MEDIUM N/A
The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.
CVE-1999-0288 1 Microsoft 1 Windows Nt 2026-06-16 5.0 MEDIUM N/A
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.
CVE-1999-0285 1 Microsoft 1 Windows Nt 2026-06-16 10.0 HIGH N/A
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
CVE-1999-0284 2 Ibm, Microsoft 2 Lotus Domino Mail Server, Exchange Server 2026-06-16 7.5 HIGH N/A
Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.
CVE-1999-0281 1 Microsoft 2 Internet Information Server, Internet Information Services 2026-06-16 5.0 MEDIUM N/A
Denial of service in IIS using long URLs.
CVE-1999-0280 1 Microsoft 1 Internet Explorer 2026-06-16 7.5 HIGH N/A
Remote command execution in Microsoft Internet Explorer using .lnk and .url files.