Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
1999-12-31 CVE-1999-1259 Unspecified vulnerability in Microsoft Office 98
Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information.
local
low complexity
microsoft
2.1
1999-12-31 CVE-1999-1246 Unspecified vulnerability in Microsoft Site Server 3.0
Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.
network
low complexity
microsoft
7.5
1999-12-31 CVE-1999-1233 Unspecified vulnerability in Microsoft Internet Information Server 4.0
IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.
network
low complexity
microsoft
7.5
1999-12-31 CVE-1999-1223 Unspecified vulnerability in Microsoft Internet Information Server 3.0
IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-1222 Unspecified vulnerability in Microsoft Windows NT 4.0
Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-1157 Denial-Of-Service vulnerability in Windows NT
Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-1148 Unspecified vulnerability in Microsoft Internet Information Server
FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-1132 Unspecified vulnerability in Microsoft Windows NT 4.0
Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-1127 Missing Release of Resource after Effective Lifetime vulnerability in Microsoft Windows NT 4.0
Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability.
network
low complexity
microsoft CWE-772
7.5
1999-12-31 CVE-1999-1105 Unspecified vulnerability in Microsoft Windows 95
Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive.
network
low complexity
microsoft
5.0