Search: "microsoft"

7712 CVEs found

Remote command execution in Microsoft Internet Explorer using .lnk and .url files.

Published: 1997-04-01
Products: 2
Vendors:
microsoft

Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.

Published: 1998-02-06
Products: 6
Vendors:
netscape microsoft

Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privile...

Published: 1998-06-29
Products: 1
Vendors:
microsoft
CVE-1999-0288
5.0 MEDIUM

The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstr...

Published: 1998-08-01
Products: 4
Vendors:
microsoft
CVE-1999-1291
5.0 MEDIUM

TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the ta...

Published: 1998-10-05
Products: 2
Vendors:
microsoft
CVE-1999-0364
10.0 HIGH

Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.

Published: 1999-01-01
Products: 2
Vendors:
fms_inc. microsoft
CVE-1999-1544
5.0 MEDIUM

Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.

Published: 1999-01-24
Products: 2
Vendors:
microsoft

Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.

Published: 1999-02-22
Products: 1
Vendors:
microsoft
CVE-1999-0386
5.0 MEDIUM

Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.

Published: 1999-03-01
Products: 2
Vendors:
microsoft
CVE-1999-0419
5.0 MEDIUM

When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.

Published: 1999-03-01
Products: 0

Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.

Published: 1999-04-09
Products: 1
Vendors:
microsoft
CVE-1999-1097
6.4 MEDIUM

Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.

Published: 1999-05-04
Products: 1
Vendors:
microsoft

A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.

Published: 1999-05-07
Products: 6
Vendors:
microsoft
CVE-1999-1033
5.0 MEDIUM

Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 ses...

Published: 1999-05-11
Products: 3
Vendors:
microsoft
CVE-1999-1520
5.0 MEDIUM

A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.

Published: 1999-05-11
Products: 1
Vendors:
microsoft

AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detectio...

Published: 1999-05-12
Products: 1
Vendors:
broadcom
CVE-1999-1164
5.0 MEDIUM

Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.

Published: 1999-06-25
Products: 4
Vendors:
microsoft
CVE-1999-1011
10.0 HIGH

The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.

Published: 1999-07-19
Products: 7
Vendors:
microsoft

The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.

Published: 1999-07-28
Products: 3
Vendors:
microsoft
CVE-1999-0700
6.2 MEDIUM

Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.

Published: 1999-07-29
Products: 8
Vendors:
microsoft