Filtered by vendor Microsoft
Subscribe
Total
21800 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2002-1291 | 1 Microsoft | 1 Java Virtual Machine | 2016-10-18 | 5.0 MEDIUM | N/A |
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL. | |||||
CVE-2002-1288 | 1 Microsoft | 1 Java Virtual Machine | 2016-10-18 | 5.0 MEDIUM | N/A |
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call. | |||||
CVE-2002-1289 | 1 Microsoft | 1 Java Virtual Machine | 2016-10-18 | 7.5 HIGH | N/A |
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an instance of the com.ms.awt.peer.INativeServices (INativeServices) class, whose methods do not verify the memory addresses that are passed as parameters. | |||||
CVE-2002-1294 | 1 Microsoft | 1 Java Virtual Machine | 2016-10-18 | 7.5 HIGH | N/A |
The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to access proprietary Microsoft methods. | |||||
CVE-2002-1290 | 1 Microsoft | 1 Java Virtual Machine | 2016-10-18 | 6.4 MEDIUM | N/A |
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class. | |||||
CVE-2002-1287 | 1 Microsoft | 1 Java Virtual Machine | 2016-10-18 | 5.0 MEDIUM | N/A |
Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass. | |||||
CVE-2002-1293 | 1 Microsoft | 1 Java Virtual Machine | 2016-10-18 | 7.5 HIGH | N/A |
The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method. | |||||
CVE-2002-1150 | 1 Microsoft | 1 Netmeeting | 2016-10-18 | 4.6 MEDIUM | N/A |
The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL) and canceling out of the resulting user confirmation prompts, such as when the remote user is editing a document. | |||||
CVE-2002-0975 | 1 Microsoft | 1 Directx Files Viewer Control | 2016-10-18 | 7.5 HIGH | N/A |
Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter. | |||||
CVE-2002-0982 | 1 Microsoft | 1 Sql Server | 2016-10-18 | 7.5 HIGH | N/A |
Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MScopyscript stored procedure. | |||||
CVE-2002-0979 | 1 Microsoft | 1 Virtual Machine | 2016-10-18 | 7.5 HIGH | N/A |
The Java logging feature for the Java Virtual Machine in Internet Explorer writes output from functions such as System.out.println to a known pathname, which can be used to execute arbitrary code. | |||||
CVE-2002-0729 | 1 Microsoft | 1 Sql Server | 2016-10-18 | 5.0 MEDIUM | N/A |
Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator. | |||||
CVE-2002-0409 | 1 Microsoft | 1 .net Framework | 2016-10-18 | 5.0 MEDIUM | N/A |
orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter. | |||||
CVE-2002-0340 | 1 Microsoft | 1 Windows Media Player | 2016-10-18 | 7.5 HIGH | N/A |
Windows Media Player (WMP) 8.00.00.4477, and possibly other versions, automatically detects and executes .wmf and other content, even when the file's extension or content type does not specify .wmf, which could make it easier for attackers to conduct unauthorized activities via Trojan horse files containing .wmf content. | |||||
CVE-2002-0285 | 1 Microsoft | 1 Outlook Express | 2016-10-18 | 7.5 HIGH | N/A |
Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to bypass virus protection and or other filtering mechanisms via a mail message with headers that only contain the CR, which causes Outlook to create separate headers. | |||||
CVE-2002-0283 | 1 Microsoft | 1 Windows Xp | 2016-10-18 | 5.0 MEDIUM | N/A |
Windows XP with port 445 open allows remote attackers to cause a denial of service (CPU consumption) via a flood of TCP SYN packets containing possibly malformed data. | |||||
CVE-2001-0945 | 1 Microsoft | 1 Outlook Express | 2016-10-18 | 5.0 MEDIUM | N/A |
Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line. | |||||
CVE-2000-0347 | 1 Microsoft | 2 Windows 95, Windows 98 | 2016-10-18 | 5.0 MEDIUM | N/A |
Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name. | |||||
CVE-1999-1538 | 1 Microsoft | 1 Internet Information Server | 2016-10-18 | 2.1 LOW | N/A |
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password. | |||||
CVE-1999-1544 | 1 Microsoft | 1 Internet Information Server | 2016-10-18 | 5.0 MEDIUM | N/A |
Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command. |