58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2004-0567 | HIGH 7.5 | microsoft windows_2000 The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers | 68.7% | — |
| CVE-2004-0566 | HIGH 7.5 | microsoft internet_explorer Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value. | 38.5% | — |
| CVE-2004-0488 | HIGH 7.5 | apache http_server Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN. | 37.7% | — |
| CVE-2004-0206 | HIGH 7.5 | microsoft windows_2000 Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application th | 74.7% | — |
| CVE-2004-0204 | HIGH 7.5 | bea weblogic_server Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and oth | 72.4% | — |
| CVE-2004-0197 | HIGH 7.5 | microsoft jet Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query. | 26.3% | — |
| CVE-2004-0174 | HIGH 7.5 | apache http_server Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket. | 11.5% | — |
| CVE-2004-0123 | HIGH 7.5 | microsoft windows_2000 Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code. | 29.7% | — |
| CVE-2004-0121 | HIGH 7.5 | microsoft office Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arb | 47.7% | — |
| CVE-2004-0119 | HIGH 7.5 | microsoft windows_2000 The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit reques | 39.6% | — |
| CVE-2004-0117 | HIGH 7.5 | microsoft netmeeting Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code. | 26.5% | — |
| CVE-2004-0079 | HIGH 7.5 | 4d webstar The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference. | 9.5% | — |
| CVE-2004-0054 | HIGH 7.5 | cisco ios Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol | 4.6% | — |
| CVE-2004-0044 | HIGH 7.5 | cisco personal_assistant Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers | 1.7% | — |
| CVE-2003-1604 | HIGH 7.5 | linux linux_kernel The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT.c in the Linux kernel before 2.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending packets to an interface that has a 0.0.0.0 IP address, a rela | 3.8% | — |
| CVE-2003-1567 | HIGH 7.5 | microsoft internet_information_services The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass th | 25.2% | — |
| CVE-2003-1332 | HIGH 7.5 | samba samba Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2003-0201. | 5.0% | — |
| CVE-2003-1328 | HIGH 7.5 | microsoft ie The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Valida | 38.9% | — |
| CVE-2003-1326 | HIGH 7.5 | microsoft ie Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box." | 16.3% | — |
| CVE-2003-1109 | HIGH 7.5 | cisco ios The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arb | 6.8% | — |
| CVE-2003-1041 | HIGH 7.5 | microsoft ie Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not h | 52.6% | — |
| CVE-2003-0995 | HIGH 7.5 | microsoft windows_2000 Buffer overflow in the Microsoft Message Queue Manager (MSQM) allows remote attackers to cause a denial of service (RPC service crash) via a queue registration request. | 10.0% | — |
| CVE-2003-0993 | HIGH 7.5 | apache http_server mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions. | 10.8% | — |
| CVE-2003-0987 | HIGH 7.5 | apache http_server mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret. | 5.6% | — |
| CVE-2003-0983 | HIGH 7.5 | cisco 80-7111-01_for_the_unity-svrx255-1a Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bubba" local user account, (2) an open TCP port 34571, or (3) w | 1.9% | — |