Filtered by vendor Microsoft
Subscribe
Total
17397 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2000-0129 | 1 Microsoft | 3 Windows 95, Windows 98, Windows Nt | 2022-08-17 | 2.1 LOW | N/A |
Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file. | |||||
CVE-2000-0114 | 1 Microsoft | 1 Internet Information Server | 2022-08-17 | 5.0 MEDIUM | N/A |
Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. | |||||
CVE-2000-0081 | 1 Microsoft | 1 Hotmail | 2022-08-17 | 10.0 HIGH | N/A |
Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript. | |||||
CVE-2000-0028 | 1 Microsoft | 2 Ie, Internet Explorer | 2022-08-17 | 2.6 LOW | N/A |
Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function. | |||||
CVE-1999-0546 | 1 Microsoft | 1 Windows Nt | 2022-08-17 | 4.6 MEDIUM | N/A |
The Windows NT guest account is enabled. | |||||
CVE-1999-0289 | 2 Apache, Microsoft | 2 Http Server, Windows | 2022-08-17 | 5.0 MEDIUM | N/A |
The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL. | |||||
CVE-2000-0126 | 1 Microsoft | 1 Internet Information Server | 2022-08-17 | 5.0 MEDIUM | N/A |
Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack. | |||||
CVE-1999-0506 | 1 Microsoft | 2 Windows 2000, Windows Nt | 2022-08-17 | 7.2 HIGH | N/A |
A Windows NT domain user or administrator account has a default, null, blank, or missing password. | |||||
CVE-1999-0505 | 1 Microsoft | 2 Windows 2000, Windows Nt | 2022-08-17 | 7.2 HIGH | N/A |
A Windows NT domain user or administrator account has a guessable password. | |||||
CVE-1999-0827 | 2 Microsoft, Netscape | 3 Ie, Internet Explorer, Navigator | 2022-08-17 | 2.6 LOW | N/A |
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. | |||||
CVE-1999-0331 | 1 Microsoft | 1 Internet Explorer | 2022-08-17 | 7.5 HIGH | N/A |
Buffer overflow in Internet Explorer 4.0(1). | |||||
CVE-1999-0519 | 1 Microsoft | 4 Outlook, Windows 2000, Windows 95 and 1 more | 2022-08-17 | 7.5 HIGH | N/A |
A NETBIOS/SMB share password is the default, null, or missing. | |||||
CVE-1999-0535 | 1 Microsoft | 2 Windows 2000, Windows Nt | 2022-08-17 | 10.0 HIGH | N/A |
A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness. | |||||
CVE-1999-0503 | 1 Microsoft | 2 Windows 2000, Windows Nt | 2022-08-17 | 7.2 HIGH | N/A |
A Windows NT local user or administrator account has a guessable password. | |||||
CVE-1999-0294 | 1 Microsoft | 1 Wins | 2022-08-17 | 5.0 MEDIUM | N/A |
All records in a WINS database can be deleted through SNMP for a denial of service. | |||||
CVE-1999-0281 | 1 Microsoft | 2 Internet Information Server, Internet Information Services | 2022-08-17 | 5.0 MEDIUM | N/A |
Denial of service in IIS using long URLs. | |||||
CVE-1999-0570 | 1 Microsoft | 1 Windows Nt | 2022-08-17 | 10.0 HIGH | N/A |
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. | |||||
CVE-1999-0292 | 1 Microsoft | 1 Windows Nt | 2022-08-17 | 5.0 MEDIUM | N/A |
Denial of service through Winpopup using large user names. | |||||
CVE-1999-0549 | 1 Microsoft | 1 Windows Nt | 2022-08-17 | 7.2 HIGH | N/A |
Windows NT automatically logs in an administrator upon rebooting. | |||||
CVE-1999-0469 | 1 Microsoft | 1 Internet Explorer | 2022-08-17 | 5.0 MEDIUM | N/A |
Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client. |