VendorsMicrosoftwindows_95all versions
Vulnerabilities

Microsoft Windows 95

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-1999-1291
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.
Published 2001-09-12 · Modified
5.0EPSS 0.133
CVE-2000-0980
NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network.
Published 2001-01-22 · Modified
5.0EPSS 0.132
CVE-1999-0104
A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.
Published 2000-02-04 · Modified
5.0EPSS 0.093
CVE-2000-0612
Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table.
Published 2000-07-19 · Modified
5.0EPSS 0.086
CVE-2007-2186
Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
Published 2007-04-24 · Modified
5.01 PoCEPSS 0.076
CVE-1999-0258
Bonk variation of teardrop IP fragmentation denial of service.
Published 2000-02-04 · Modified
5.0EPSS 0.060
CVE-1999-0179
Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.
Published 1999-09-29 · Modified
5.0EPSS 0.060
CVE-2006-7039
The IMAP4 service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (crash) via a message with a long subject field.
Published 2007-02-23 · Modified
5.0EPSS 0.015
CVE-2003-1569
GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385.
Published 2009-02-06 · Modified
5.0EPSS 0.011
CVE-1999-0975
The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.
Published 2000-01-04 · Modified
4.61 PoCEPSS 0.027
CVE-1999-1104
Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.
Published 2002-03-09 · Modified
4.6EPSS 0.010
CVE-2006-7037
Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by replacing the password field with a hash of a known password, (2) modify timestamps to avoid detection of modifications, (3) remove locks by removing the "is-locked" attribute, and (4) view locked data, which is stored in plaintext.
Published 2007-02-23 · Modified
4.4EPSS 0.003
CVE-2002-1692
Buffer overflow in backup utility of Microsoft Windows 95 allows attackers to execute arbitrary code by causing a filename with a long extension to be placed in a folder to be backed up.
Published 2005-06-21 · Modified
3.6EPSS 0.015
CVE-2000-1003
NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash.
Published 2001-01-22 · Modified
2.6EPSS 0.125
CVE-1999-0749
Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.
Published 2000-01-04 · Modified
2.61 PoCEPSS 0.080
CVE-1999-0717
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
Published 2000-01-04 · Modified
2.6EPSS 0.058
CVE-2000-0129
Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.
Published 2000-02-08 · Modified
2.11 PoCEPSS 0.038
← Prev2 / 2