Skip to main content

Vendor archive

microsoft CVEs

Beta · best-effort

25,487 CVEs tagged to vendor microsoft3,866 Critical, 13,519 High, 7,489 Medium, 612 Low, 1 Unrated.

CVE-2001-1515

Published Dec 31, 2001

Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the direct…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1517

Published Dec 31, 2001

RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1518

Published Dec 31, 2001

RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1519

Published Dec 31, 2001

RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connec…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1533

Published Dec 31, 2001

Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disput…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1539

Published Dec 31, 2001

Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the J…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1547

Published Dec 31, 2001

Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, does not block email attachments from forwarded messages, whi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1552

Published Dec 31, 2001

ssdpsrv.exe in Windows ME allows remote attackers to cause a denial of service by sending multiple newlines in a Simple Service Discovery Protocol (SSDP) message. NOTE: multiple…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1560

Published Dec 31, 2001

Win32k.sys (aka Graphics Device Interface (GDI)) in Windows 2000 and XP allows local users to cause a denial of service (system crash) by calling the ShowWindow function after rec…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1570

Published Dec 31, 2001

Windows XP with fast user switching and account lockout enabled allows local users to deny user account access by setting the fast user switch to the same user (self) multiple tim…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1571

Published Dec 31, 2001

The Remote Desktop client in Windows XP sends the most recent user account name in cleartext, which could allow remote attackers to obtain terminal server user account names via s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0542

Published Dec 20, 2001

Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, o…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-1218

Published Dec 20, 2001

Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese cha…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1219

Published Dec 20, 2001

Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1200

Published Dec 17, 2001

Microsoft Windows XP allows local users to bypass a locked screen and run certain programs that are associated with Hot Keys.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0727

Published Dec 14, 2001

Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0874

Published Dec 13, 2001

Internet Explorer 5.5 and 6.0 allow remote attackers to read certain files via HTML that passes information from a frame in the client's domain to a frame in the web site's domain…

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-1186

Published Dec 11, 2001

Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0951

Published Dec 7, 2001

Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (IKE) UDP port 500 with packets that contain a large number o…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0663

Published Dec 6, 2001

Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0719

Published Dec 6, 2001

Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file.

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 25,001-25,025 of 25,487 CVEsPage 1001 of 1020