Skip to main content

Vendor archive

microsoft CVEs

Beta · best-effort

25,970 CVEs tagged to vendor microsoft3,910 Critical, 13,826 High, 7,621 Medium, 612 Low, 1 Unrated.

CVE-2006-4066

Published Aug 10, 2006

The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certa…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-3443

Published Aug 9, 2006

Untrusted search path vulnerability in Winlogon in Microsoft Windows 2000 SP4, when SafeDllSearchMode is disabled, allows local users to gain privileges via a malicious DLL in the…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3438

Published Aug 9, 2006

Unspecified vulnerability in Microsoft Hyperlink Object Library (hlink.dll), possibly a buffer overflow, allows user-assisted attackers to execute arbitrary code via crafted hyper…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-3444

Published Aug 9, 2006

Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, probably a buffer overflow, allows local users to obtain privileges via unspecified vectors involving an "un…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3449

Published Aug 9, 2006

Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malforme…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3639

Published Aug 9, 2006

Microsoft Internet Explorer 5.01 and 6 does not properly identify the originating domain zone when handling redirects, which allows remote attackers to read cross-domain web pages…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3640

Published Aug 9, 2006

Microsoft Internet Explorer 5.01 and 6 allows certain script to persist across navigations between pages, which allows remote attackers to obtain the window location of visited we…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3643

Published Aug 9, 2006

Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Mana…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3649

Published Aug 9, 2006

Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Acce…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3450

Published Aug 8, 2006

Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access crafted Cascading Style Sheet (C…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3451

Published Aug 8, 2006

Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are used on a styleSheets collection" to construct a chain of Cascading Style Sheets…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3637

Published Aug 8, 2006

Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary co…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3638

Published Aug 8, 2006

Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3943

Published Jul 31, 2006

Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via long (1) RGBExtra…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-3944

Published Jul 31, 2006

Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via a (1) Forms.ListBox.1 or (2) Forms.ListBox.1 object with the ListW…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3945

Published Jul 31, 2006

The CSS functionality in Opera 9 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by setting the background property of a DHTML element to a long htt…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3910

Published Jul 28, 2006

Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a denial of service (crash) by calling the NewDefaultItem function of an OVCtl (…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3915

Published Jul 28, 2006

Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by iterating over any native function, as demonstrated with the window…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 24,626-24,650 of 25,970 CVEsPage 986 of 1039