Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
1999-12-31 CVE-1999-1104 Unspecified vulnerability in Microsoft Windows 95
Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.
local
low complexity
microsoft
4.6
1999-12-31 CVE-1999-1094 Unspecified vulnerability in Microsoft Internet Explorer
Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."
network
low complexity
microsoft
7.5
1999-12-31 CVE-1999-1093 Unspecified vulnerability in Microsoft Internet Explorer 4.0/4.0.1
Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.
network
high complexity
microsoft
5.1
1999-12-31 CVE-1999-1087 Unspecified vulnerability in Microsoft Internet Explorer 4.0/4.0.1
Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.
network
low complexity
microsoft
7.5
1999-12-31 CVE-1999-1084 Unspecified vulnerability in Microsoft Windows NT 4.0
The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.
local
low complexity
microsoft
4.6
1999-12-31 CVE-1999-1055 Unspecified vulnerability in Microsoft Excel 97
Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."
network
low complexity
microsoft
7.5
1999-12-31 CVE-1999-1043 Unspecified vulnerability in Microsoft Exchange Server 5.0/5.5
Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-1035 Unspecified vulnerability in Microsoft Internet Information Server 3.0/4.0
IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-0815 Unspecified vulnerability in Microsoft Windows NT 4.0
Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-0154 Unspecified vulnerability in Microsoft products
IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a .
network
low complexity
microsoft
5.0