Filtered by vendor Microsoft
Subscriptions
Total
20250 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-1999-1538 | 1 Microsoft | 1 Internet Information Server | 2024-08-01 | N/A |
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password. | ||||
CVE-1999-1544 | 1 Microsoft | 1 Internet Information Server | 2024-08-01 | N/A |
Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command. | ||||
CVE-1999-1474 | 1 Microsoft | 1 Powerpoint | 2024-08-01 | N/A |
PowerPoint 95 and 97 allows remote attackers to cause an application to be run automatically without prompting the user, possibly through the slide show, when the document is opened in browsers such as Internet Explorer. | ||||
CVE-1999-1473 | 1 Microsoft | 1 Internet Explorer | 2024-08-01 | N/A |
When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue." | ||||
CVE-1999-1520 | 1 Microsoft | 1 Site Server | 2024-08-01 | N/A |
A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information. | ||||
CVE-1999-1484 | 1 Microsoft | 1 Msn Setup Bulletin Board Services | 2024-08-01 | N/A |
Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured. | ||||
CVE-1999-1463 | 1 Microsoft | 1 Windows Nt | 2024-08-01 | N/A |
Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session. | ||||
CVE-1999-1472 | 1 Microsoft | 1 Internet Explorer | 2024-08-01 | N/A |
Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue. | ||||
CVE-1999-1478 | 1 Microsoft | 1 Internet Information Server | 2024-08-01 | N/A |
The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character. | ||||
CVE-1999-1451 | 1 Microsoft | 2 Internet Information Server, Site Server | 2024-08-01 | N/A |
The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files. | ||||
CVE-1999-1452 | 1 Microsoft | 1 Windows Nt | 2024-08-01 | N/A |
GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt. | ||||
CVE-1999-1455 | 1 Microsoft | 1 Windows Nt | 2024-08-01 | N/A |
RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host. | ||||
CVE-1999-1362 | 1 Microsoft | 1 Windows Nt | 2024-08-01 | N/A |
Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters. | ||||
CVE-1999-1431 | 1 Microsoft | 1 Zero Administration Kit | 2024-08-01 | N/A |
ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe. | ||||
CVE-1999-1367 | 1 Microsoft | 1 Internet Explorer | 2024-08-01 | N/A |
Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users. | ||||
CVE-1999-1370 | 1 Microsoft | 1 Internet Explorer | 2024-08-01 | N/A |
The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs. | ||||
CVE-1999-1397 | 1 Microsoft | 1 Index Server | 2024-08-01 | N/A |
Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed. | ||||
CVE-1999-1446 | 1 Microsoft | 1 Internet Explorer | 2024-08-01 | N/A |
Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays. | ||||
CVE-1999-1317 | 1 Microsoft | 1 Windows Nt | 2024-08-01 | N/A |
Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device. | ||||
CVE-1999-1453 | 1 Microsoft | 1 Internet Explorer | 2024-08-01 | N/A |
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. |