Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
1999-03-12 CVE-1999-0382 Unspecified vulnerability in Microsoft Windows NT 3.5.1/4.0
The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.
local
low complexity
microsoft
7.2
1999-03-08 CVE-1999-1254 Unspecified vulnerability in Microsoft Windows 95, Windows 98 and Windows NT
Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.
network
low complexity
microsoft
5.0
1999-03-01 CVE-1999-0386 Unspecified vulnerability in Microsoft Frontpage and Personal web Server
Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.
network
low complexity
microsoft
5.0
1999-02-22 CVE-1999-0379 Unspecified vulnerability in Microsoft Backoffice Resource KIT 2.0
Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.
network
low complexity
microsoft
7.5
1999-02-20 CVE-1999-0376 Unspecified vulnerability in Microsoft Windows NT 3.5.1/4.0
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.
local
low complexity
microsoft
4.6
1999-02-19 CVE-1999-0412 Unspecified vulnerability in Microsoft products
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
network
low complexity
microsoft
7.5
1999-02-11 CVE-1999-1375 Unspecified vulnerability in Microsoft Internet Information Server 3.0/4.0
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.
network
low complexity
microsoft
5.0
1999-02-09 CVE-1999-0407 Unspecified vulnerability in Microsoft Internet Information Server 4.0
By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.
network
low complexity
microsoft
critical
10.0
1999-02-06 CVE-1999-1201 Unspecified vulnerability in Microsoft Windows 95 and Windows 98
Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing.
network
low complexity
microsoft
5.0
1999-02-02 CVE-1999-1453 Unspecified vulnerability in Microsoft Internet Explorer 4.0
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.
network
high complexity
microsoft
2.6