Skip to main content

Vendor archive

microsoft CVEs

Beta · best-effort

25,487 CVEs tagged to vendor microsoft3,866 Critical, 13,519 High, 7,489 Medium, 612 Low, 1 Unrated.

CVE-2001-0722

Published Dec 6, 2001

Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."

CVSS 6.4 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0726

Published Dec 6, 2001

Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to pe…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0807

Published Dec 6, 2001

Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SR…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-0860

Published Dec 6, 2001

Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0945

Published Dec 3, 2001

Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0875

Published Nov 26, 2001

Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users i…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0919

Published Nov 26, 2001

Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0909

Published Nov 21, 2001

Buffer overflow in helpctr.exe program in Microsoft Help Center for Windows XP allows remote attackers to execute arbitrary code via a long hcp: URL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0902

Published Nov 20, 2001

Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0904

Published Nov 20, 2001

Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgent) information that indicates that the patch has been installed, which could al…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0723

Published Nov 14, 2001

Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability."

CVSS 6.4 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0724

Published Nov 14, 2001

Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the p…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0505

Published Oct 30, 2001

Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) th…

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0540

Published Oct 30, 2001

Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desk…

CVSS 5.0 · Medium
Buzz score
8.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0544

Published Oct 30, 2001

IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type tab…

CVSS 2.1 · Low
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0545

Published Oct 30, 2001

IIS 4.0 with URL redirection enabled allows remote attackers to cause a denial of service (crash) via a malformed request that specifies a length that is different than the actual…

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0660

Published Oct 30, 2001

Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresses by directly accessing a back-end function that…

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0662

Published Oct 30, 2001

RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed request.

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0664

Published Oct 30, 2001

Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to proc…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0665

Published Oct 30, 2001

Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers t…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0666

Published Oct 30, 2001

Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested fol…

CVSS 2.1 · Low
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0667

Published Oct 30, 2001

Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file op…

CVSS 7.3 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0712

Published Oct 30, 2001

The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0718

Published Oct 30, 2001

Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 25,026-25,050 of 25,487 CVEsPage 1002 of 1020