58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2005-2940 | HIGH 7.2 | microsoft antispyware Unquoted Windows search path vulnerability in Microsoft Antispyware 1.0.509 (Beta 1) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, involving the programs (1) GIANTAntiSpywareMain.exe, (2) gcASNotice.exe, (3) gc | 2.3% | — |
| CVE-2005-2939 | HIGH 7.2 | vmware workstation Unquoted Windows search path vulnerability in VMWare Workstation 5.0.0 build-13124 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder. | 0.3% | — |
| CVE-2005-2827 | HIGH 7.2 | microsoft windows_2000 The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow via steps in which a terminating thread causes Asynchronous Procedure Call (APC) entries to free the wrong dat | 2.6% | — |
| CVE-2005-2681 | HIGH 7.2 | cisco ips_sensor_software Unspecified vulnerability in the command line processing (CLI) logic in Cisco Intrusion Prevention System 5.0(1) and 5.0(2) allows local users with OPERATOR or VIEWER privileges to gain additional privileges via unknown vectors. | 0.4% | — |
| CVE-2005-2388 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in a certain USB driver, as used on Microsoft Windows, allows attackers to execute arbitrary code. | 1.8% | — |
| CVE-2005-1589 | HIGH 7.2 | linux linux_kernel The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessibl | 1.2% | — |
| CVE-2005-1264 | HIGH 7.2 | linux linux_kernel Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space, a similar vulnerability to CVE-2005-1589. | 0.5% | — |
| CVE-2005-1263 | HIGH 7.2 | linux linux_kernel The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, | 1.8% | — |
| CVE-2005-1207 | HIGH 7.2 | microsoft windows_2003_server Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters. | 7.3% | — |
| CVE-2005-0867 | HIGH 7.2 | linux linux_kernel Integer overflow in Linux kernel 2.6 allows local users to overwrite kernel memory by writing to a sysfs file. | 0.4% | — |
| CVE-2005-0839 | HIGH 7.2 | linux linux_kernel Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE line discipline for a TTY, which allows local users to gain privileges by injecting mouse or keyboard events into other user sessions. | 0.4% | — |
| CVE-2005-0750 | HIGH 7.2 | conectiva linux The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value. | 0.8% | — |
| CVE-2005-0749 | HIGH 7.2 | linux linux_kernel The load_elf_library in the Linux kernel before 2.6.11.6 allows local users to cause a denial of service (kernel crash) via a crafted ELF library or executable, which causes a free of an invalid pointer. | 0.4% | — |
| CVE-2005-0545 | HIGH 7.2 | microsoft windows_2000 Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash dri | 1.8% | — |
| CVE-2005-0061 | HIGH 7.2 | microsoft windows_2000 The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests. | 1.8% | — |
| CVE-2005-0060 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application. | 1.7% | — |
| CVE-2005-0047 | HIGH 7.2 | microsoft windows_2000 Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability." | 4.4% | — |
| CVE-2004-2515 | HIGH 7.2 | vmware workstation Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or | 0.5% | — |
| CVE-2004-2343 | HIGH 7.2 | apache http_server Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess | 0.6% | — |
| CVE-2004-1649 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future. | 2.4% | — |
| CVE-2004-1151 | HIGH 7.2 | linux linux_kernel Multiple buffer overflows in the (1) sys32_ni_syscall and (2) sys32_vm86_warning functions in sys_ia32.c for Linux 2.6.x may allow local attackers to modify kernel memory and gain privileges. | 0.4% | — |
| CVE-2004-1144 | HIGH 7.2 | linux linux_kernel Unknown vulnerability in the 32bit emulation code in Linux 2.4 on AMD64 systems allows local users to gain privileges. | 0.4% | — |
| CVE-2004-1072 | HIGH 7.2 | linux linux_kernel The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow | 0.6% | — |
| CVE-2004-1071 | HIGH 7.2 | linux linux_kernel The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code. | 0.5% | — |
| CVE-2004-1070 | HIGH 7.2 | linux linux_kernel The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory | 0.5% | — |