Skip to main content

Vendor archive

microsoft CVEs

Beta · best-effort

25,487 CVEs tagged to vendor microsoft3,866 Critical, 13,519 High, 7,489 Medium, 612 Low, 1 Unrated.

CVE-1999-1397

Published Mar 23, 1999

Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0382

Published Mar 12, 1999

The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.

CVSS 7.2 · High
Buzz score
11.5
Public PoC observedOTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-0386

Published Mar 1, 1999

Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-0379

Published Feb 22, 1999

Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-0376

Published Feb 20, 1999

Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.

CVSS 4.6 · Medium
Buzz score
7.5
Public PoC observedOTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-1375

Published Feb 11, 1999

FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0407

Published Feb 9, 1999

By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.

CVSS 10.0 · Critical
Buzz score
10.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-1999-0366

Published Feb 8, 1999

In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-1201

Published Feb 6, 1999

Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplific…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-1453

Published Feb 2, 1999

Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-1999-0360

Published Jan 30, 1999

MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0349

Published Jan 27, 1999

A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.

CVSS 7.5 · High
Buzz score
22.0
Public PoC observedOTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-0449

Published Jan 26, 1999

The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0357

Published Jan 25, 1999

Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-1544

Published Jan 24, 1999

Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0119

Published Jan 19, 1999

Windows NT 4.0 beta allows users to read and delete shares.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1376

Published Jan 14, 1999

Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-1538

Published Jan 14, 1999

When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to ga…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-1999-0226

Published Jan 1, 1999

Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 25,451-25,475 of 25,487 CVEsPage 1019 of 1020