58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2003-0659 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application. | 43.0% | — |
| CVE-2003-0631 | HIGH 7.2 | vmware gsx_server VMware GSX Server 2.5.1 build 4968 and earlier, and Workstation 4.0 and earlier, allows local users to gain root privileges via certain enivronment variables that are used when launching a virtual machine session. | 0.4% | — |
| CVE-2003-0542 | HIGH 7.2 | apache http_server Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures. | 30.4% | — |
| CVE-2003-0496 | HIGH 7.2 | microsoft windows_2000 Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file. | 4.6% | — |
| CVE-2003-0306 | HIGH 7.2 | microsoft windows_xp Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter. | 4.0% | — |
| CVE-2003-0232 | HIGH 7.2 | microsoft data_engine Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow. | 4.1% | — |
| CVE-2003-0230 | HIGH 7.2 | microsoft data_engine Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability. | 2.3% | — |
| CVE-2003-0127 | HIGH 7.2 | linux linux_kernel The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel. | 1.6% | — |
| CVE-2003-0004 | HIGH 7.2 | microsoft windows_xp Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter. | 3.1% | — |
| CVE-2002-2324 | HIGH 7.2 | microsoft windows_xp The "System Restore" directory and subdirectories, and possibly other subdirectories in the "System Volume Information" directory on Windows XP Professional, have insecure access control list (ACL) permissions, which allows local users to access restricted fil | 1.8% | — |
| CVE-2002-1933 | HIGH 7.2 | microsoft windows_2000_terminal_services The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window. | 1.6% | — |
| CVE-2002-1749 | HIGH 7.2 | microsoft windows_2000 Windows 2000 Terminal Services, when using the disconnect feature of the client, does not properly lock itself if it is left idle until the screen saver activates and the user disconnects, which could allow attackers to gain administrator privileges. | 1.5% | — |
| CVE-2002-1492 | HIGH 7.2 | cisco vpn_5000_client Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to gain root privileges via (1) close_tunnel and (2) open_tunnel. | 1.7% | — |
| CVE-2002-1447 | HIGH 7.2 | cisco vpn_client Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument. | 1.5% | — |
| CVE-2002-0839 | HIGH 7.2 | apache http_server The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not | 0.9% | — |
| CVE-2002-0720 | HIGH 7.2 | microsoft windows_2000 A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code. | 2.2% | — |
| CVE-2002-0642 | HIGH 7.2 | microsoft msde The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on | 49.7% | — |
| CVE-2002-0373 | HIGH 7.2 | microsoft windows_media_player The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Privileg | 1.8% | — |
| CVE-2002-0366 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry. | 2.8% | — |
| CVE-2002-0151 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request. | 3.3% | — |
| CVE-2001-1384 | HIGH 7.2 | linux linux_kernel ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or setgid program that itself calls an unprivileged program, such as newgrp. | 1.0% | — |
| CVE-2001-1200 | HIGH 7.2 | microsoft windows_xp Microsoft Windows XP allows local users to bypass a locked screen and run certain programs that are associated with Hot Keys. | 2.5% | — |
| CVE-2001-0628 | HIGH 7.2 | microsoft word Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user. | 2.2% | — |
| CVE-2001-0507 | HIGH 7.2 | microsoft internet_information_services IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability. | 8.8% | — |
| CVE-2001-0506 | HIGH 7.2 | microsoft internet_information_server Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnera | 68.9% | — |