Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Windows Number Of NVD 3854 CRITICAL 65 HIGH 2644 MEDIUM 1087 LOW 58
URL https://www.microsoft.com/
Explanation For business, developer, and desktop operating system products, 10 years of support at the supported Service Pack level (with a minimum of 5 years of mainstream support, followed by a minimum of 5 years of extended support).
You may need to deploy the latest updates to be eligible for support.
For some products, the support organization may be less than 10 years.

For consumer and multimedia products, five years of mainstream support at the supported Service Pack level.

The above text is excerpted from Microsoft's Fixed Lifecycle Policy.
Tag
  • Microsoft
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.microsoft.com/ja-jp/atlife/article-windows10-portal-eos.aspx
2 https://support.microsoft.com/help/14085/fixed-lifecycle-policy
3 https://support.microsoft.com/help/30881/modern-lifecycle-policy
4 https://support.microsoft.com//lifecycle/search
5 https://support.microsoft.com/ja-jp/hub/4095338/microsoft-lifecycle-policy
6 https://support.microsoft.com/ja-jp/help/4057281/windows-7-support-ended-on-january-14-2020
7 https://docs.microsoft.com/ja-jp/windows/release-information/
8 https://docs.microsoft.com/ja-jp/lifecycle/faq/extended-security-updates

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
3841 Windows 11 23H2 Oct. 31, 2023 Oct. 4, 2021 15 425 130 3
3842 Windows 10 (Enterprise, Education, Pro, Pro for Workstations, IoT, Home) 22H2 Oct. 18, 2022 July 29, 2015 Oct. 14, 2025 57 2049 872 33
3843 Windows Phone 8.1 June 24, 2014 July 11, 2017 0 0 0 0
3844 Windows RT 8.1 Nov. 13, 2013 Jan. 9, 2018 Jan. 10, 2023 27 1228 494 38
3845 Windows Embedded 8.1 Pro Nov. 13, 2013 Jan. 9, 2018 Jan. 10, 2023 30 1296 503 34
3846 Windows 8.1 Nov. 13, 2013 Jan. 9, 2018 Jan. 10, 2023 30 1296 503 34
3847 Windows Phone 7.8 Feb. 9, 2013 Oct. 14, 2014 0 0 0 0
3848 Windows 8 Oct. 30, 2012 Jan. 12, 2016 0 167 56 24
3849 Windows Embedded Standard 7(Service Pack 1適用) July 29, 2010 Oct. 13, 2015 Oct. 13, 2020 0 0 0 0
3850 Windows 7 Oct. 22, 2009 Jan. 13, 2015 April 9, 2013 Jan. 14, 2020 29 1407 538 31
3851 Windows Vista Jan. 25, 2007 April 10, 2012 April 13, 2010 April 11, 2017 1 264 67 20
3852 Windows XP Embedded Jan. 30, 2002 Jan. 12, 2016 2 287 85 0
3853 Windows XP Dec. 31, 2001 April 8, 2014 2 287 85 0
3854 Windows Millennium Edition Dec. 31, 2000 Dec. 31, 2003 July 11, 2006 0 1 1 0
3855 Microsoft Windows 2000 Professional March 31, 2000 June 30, 2005 July 13, 2010 2 40 19 0
3856 Windows 98 Second Edition June 30, 1999 June 30, 2002 July 11, 2006 1 1 1 0
3857 Windows 98 Standard Edition June 30, 1998 June 30, 2002 July 11, 2006 1 2 2 0
3858 Windows 95 Aug. 24, 1995 Dec. 31, 2001 0 3 2 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
3841 -
10.0
HIGH The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCsc… CWE-264
Permissions, Privileges, and Access Controls
CVE-2006-2373 cpe:2.3:o:microsoft:windows_xp:-:sp2
cpe:2.3:o:microsoft:windows_xp:-:sp1
cpe:2.3:o:microsoft:windows_xp:-:-
2019-03-27 04:17
2006-06-14
Show GitHub Exploit DB Packet Storm
3842 5.5
2.1
MEDIUM
Local
The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the… CWE-667
 Improper Locking
CVE-2006-2374 cpe:2.3:o:microsoft:windows_xp:-:sp2
cpe:2.3:o:microsoft:windows_xp:-:sp1
cpe:2.3:o:microsoft:windows_xp:-:*
2024-02-16 05:22
2006-06-14
Show GitHub Exploit DB Packet Storm
3843 -
9.3
HIGH Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows r… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2006-0005 cpe:2.3:o:microsoft:windows_xp:-:* 2019-04-30 23:27
2006-02-15
Show GitHub Exploit DB Packet Storm
3844 -
10.0
HIGH By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer. NVD-CWE-Other
CVE-2005-3595 cpe:2.3:o:microsoft:windows_xp:ibm_oem_version:sp1
cpe:2.3:o:microsoft:windows_xp:ibm_oem_version:*
2017-07-11 10:33
2005-11-16
Show GitHub Exploit DB Packet Storm
3845 -
7.5
HIGH Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-… CWE-120
Classic Buffer Overflow
CVE-2005-1987 cpe:2.3:o:microsoft:windows_xp:-:sp2
cpe:2.3:o:microsoft:windows_xp:-:sp1
cpe:2.3:o:microsoft:windows_xp:-:*
2023-11-7 10:57
2005-10-13
Show GitHub Exploit DB Packet Storm
3846 7.8
10.0
HIGH
Local
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image. CWE-415
 Double Free
CVE-2003-1048 cpe:2.3:o:microsoft:windows_98:-:*
cpe:2.3:o:microsoft:windows_98se:-:*
cpe:2.3:o:microsoft:windows_xp:-:sp1
c…
2024-02-3 00:23
2004-07-27
Show GitHub Exploit DB Packet Storm
3847 -
5.1
MEDIUM Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not qu… CWE-88
Argument Injection
CVE-2003-0907 cpe:2.3:o:microsoft:windows_xp:-:* 2024-02-14 03:00
2004-06-1
Show GitHub Exploit DB Packet Storm
3848 7.5
7.5
HIGH
Network
The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or ex… CWE-476
 NULL Pointer Dereference
CVE-2004-0119 cpe:2.3:o:microsoft:windows_xp:-:* 2024-02-16 06:44
2004-06-1
Show GitHub Exploit DB Packet Storm
3849 -
5.1
MEDIUM A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads t… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2003-0813 cpe:2.3:o:microsoft:windows_98:-:*
cpe:2.3:o:microsoft:windows_xp:-:sp1
cpe:2.3:o:microsoft:windows_xp:-:*
2024-02-16 06:19
2003-11-17
Show GitHub Exploit DB Packet Storm
3850 -
7.5
HIGH Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC c… NVD-CWE-Other
CVE-2003-0003 cpe:2.3:o:microsoft:windows_xp:-:sp1
cpe:2.3:o:microsoft:windows_xp:-:*
2019-04-30 23:27
2003-02-7
Show GitHub Exploit DB Packet Storm