Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 19962 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0750 1 Microsoft 1 Hotmail 2024-11-20 5.1 MEDIUM N/A
Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account.
CVE-1999-0749 1 Microsoft 2 Windows 95, Windows 98 2024-11-20 2.6 LOW N/A
Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.
CVE-1999-0739 1 Microsoft 1 Internet Information Server 2024-11-20 5.0 MEDIUM N/A
The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
CVE-1999-0738 1 Microsoft 1 Internet Information Server 2024-11-20 5.0 MEDIUM N/A
The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
CVE-1999-0737 1 Microsoft 1 Internet Information Server 2024-11-20 5.0 MEDIUM N/A
The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
CVE-1999-0736 1 Microsoft 1 Internet Information Server 2024-11-20 5.0 MEDIUM N/A
The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
CVE-1999-0728 1 Microsoft 1 Windows Nt 2024-11-20 7.8 HIGH N/A
A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.
CVE-1999-0726 1 Microsoft 2 Windows 2000, Windows Nt 2024-11-20 7.8 HIGH N/A
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
CVE-1999-0725 1 Microsoft 1 Internet Information Server 2024-11-20 7.1 HIGH N/A
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".
CVE-1999-0723 1 Microsoft 2 Windows 2000, Windows Nt 2024-11-20 7.1 HIGH N/A
The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.
CVE-1999-0721 1 Microsoft 2 Windows 2000, Windows Nt 2024-11-20 7.8 HIGH N/A
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
CVE-1999-0717 1 Microsoft 5 Excel, Windows 2000, Windows 95 and 2 more 2024-11-20 2.6 LOW N/A
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
CVE-1999-0716 1 Microsoft 2 Windows 2000, Windows Nt 2024-11-20 4.6 MEDIUM N/A
Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.
CVE-1999-0715 1 Microsoft 2 Windows 2000, Windows Nt 2024-11-20 4.6 MEDIUM N/A
Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.
CVE-1999-0702 1 Microsoft 1 Internet Explorer 2024-11-20 10.0 HIGH N/A
Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.
CVE-1999-0701 1 Microsoft 1 Windows Nt 2024-11-20 7.2 HIGH N/A
After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.
CVE-1999-0700 1 Microsoft 2 Windows 2000, Windows Nt 2024-11-20 6.2 MEDIUM N/A
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
CVE-1999-0682 1 Microsoft 1 Exchange Server 2024-11-20 5.0 MEDIUM N/A
Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.
CVE-1999-0681 1 Microsoft 2 Frontpage, Personal Web Server 2024-11-20 5.0 MEDIUM N/A
Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL.
CVE-1999-0680 1 Microsoft 1 Terminal Server 2024-11-20 5.0 MEDIUM N/A
Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.