Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 19339 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-1233 1 Microsoft 1 Internet Information Server 2018-10-12 7.5 HIGH N/A
IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.
CVE-1999-1148 1 Microsoft 1 Internet Information Server 2018-10-12 5.0 MEDIUM N/A
FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.
CVE-1999-1084 1 Microsoft 1 Windows Nt 2018-10-12 4.6 MEDIUM N/A
The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.
CVE-1999-1055 1 Microsoft 1 Excel 2018-10-12 7.5 HIGH N/A
Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."
CVE-1999-1035 1 Microsoft 1 Internet Information Server 2018-10-12 5.0 MEDIUM N/A
IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.
CVE-1999-0910 1 Microsoft 3 Commercial Internet System, Site Server, Site Server Commerce 2018-10-12 5.0 MEDIUM N/A
Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.
CVE-1999-0749 1 Microsoft 2 Windows 95, Windows 98 2018-10-12 2.6 LOW N/A
Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.
CVE-1999-0739 1 Microsoft 1 Internet Information Server 2018-10-12 5.0 MEDIUM N/A
The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
CVE-1999-0738 1 Microsoft 1 Internet Information Server 2018-10-12 5.0 MEDIUM N/A
The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
CVE-1999-0737 1 Microsoft 1 Internet Information Server 2018-10-12 5.0 MEDIUM N/A
The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
CVE-1999-0736 1 Microsoft 1 Internet Information Server 2018-10-12 5.0 MEDIUM N/A
The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
CVE-1999-0489 1 Microsoft 1 Windows Nt 2018-10-12 10.0 HIGH N/A
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.
CVE-1999-0386 1 Microsoft 2 Frontpage, Personal Web Server 2018-10-12 5.0 MEDIUM N/A
Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.
CVE-1999-0384 1 Microsoft 6 Office, Outlook, Project and 3 more 2018-10-12 4.6 MEDIUM N/A
The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.
CVE-1999-0382 1 Microsoft 1 Windows Nt 2018-10-12 7.2 HIGH N/A
The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.
CVE-1999-0379 1 Microsoft 1 Backoffice Resource Kit 2018-10-12 7.5 HIGH N/A
Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.
CVE-1999-0376 1 Microsoft 1 Windows Nt 2018-10-12 4.6 MEDIUM N/A
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.
CVE-1999-0278 1 Microsoft 2 Internet Information Server, Windows Nt 2018-10-12 5.0 MEDIUM N/A
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
CVE-2018-8316 1 Microsoft 8 Internet Explorer, Windows 10, Windows 7 and 5 more 2018-10-12 7.6 HIGH 7.5 HIGH
A remote code execution vulnerability exists when Internet Explorer improperly validates hyperlinks before loading executable libraries, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer 11, Internet Explorer 10.
CVE-2018-8370 1 Microsoft 3 Edge, Windows 10, Windows Server 2016 2018-10-12 4.3 MEDIUM 3.1 LOW
A information disclosure vulnerability exists when WebAudio Library improperly handles audio requests, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge.