VendorsMicrosoftwindows_ntany version
Vulnerabilities

Microsoft Windows any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

87CVEs
CVE-2008-3860
Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG editors, (2) during local group creation, (3) during HTML redirects, (4) in the HTML import, (5) in the Rich text editor, and (6) in link-page in IBM Lotus Quickr 8.1 services for Lotus Domino before Hotfix 15 allow remote attackers to inject arbitrary web script or HTML via unknown vectors, including (7) the Imported Page. NOTE: the vulnerability in the WYSIWYG editors may exist because of an incomplete fix for CVE-2008-2163.
Published 2008-08-29 · Modified
4.3EPSS 0.013
CVE-2008-2163
Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors."
Published 2008-05-13 · Modified
4.3EPSS 0.012
CVE-1999-0717
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
Published 2000-01-04 · Modified
2.6EPSS 0.058
CVE-1999-0372
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
Published 1999-09-29 · Modified
2.11 PoCEPSS 0.042
CVE-1999-1362
Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters.
Published 2002-06-25 · Modified
2.1EPSS 0.014
CVE-2003-1437
BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
Published 2007-10-23 · Modified
2.1EPSS 0.002
CVE-1999-0612
A version of finger is running that exposes valid user information to any entity on the network.
Published 1999-09-29 · Modified
n/aEPSS 0.680
← Prev3 / 3