Vulnerabilities > Microsoft > Windows 95 > High

DATE CVE VULNERABILITY TITLE RISK
2009-01-15 CVE-1999-1593 Link Following vulnerability in Microsoft Windows 2000, Windows 95 and Windows 98
Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server.
network
high complexity
microsoft CWE-59
7.6
2007-02-23 CVE-2006-7034 SQL-Injection vulnerability in Super Link Exchange Script Super Link Exchange Script 1.0
SQL injection vulnerability in directory.php in Super Link Exchange Script 1.0 might allow remote attackers to execute arbitrary SQL queries via the cat parameter.
7.5
2007-02-21 CVE-2007-1043 Authentication Bypass vulnerability in Ezboo Webstats 3.0.3
Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.
7.5
2002-12-23 CVE-2002-1260 Unspecified vulnerability in Microsoft products
The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet.
network
low complexity
microsoft
7.5
2002-03-08 CVE-2002-0053 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request.
network
low complexity
microsoft CWE-119
7.5
2001-07-02 CVE-2001-0238 Unspecified vulnerability in Microsoft products
Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.
network
low complexity
microsoft
7.5
2000-08-29 CVE-2000-1079 Unspecified vulnerability in Microsoft products
Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.
network
low complexity
microsoft
7.5
2000-05-19 CVE-2000-0305 Resource Management Errors vulnerability in multiple products
Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.
network
low complexity
be microsoft CWE-399
7.8
1999-11-12 CVE-2000-0330 Unspecified vulnerability in Microsoft Windows 95 and Windows 98
The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability.
network
high complexity
microsoft
7.6
1998-02-01 CVE-1999-0256 Buffer overflow in War FTP allows remote execution of commands.
network
low complexity
jgaa microsoft
7.5