58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2001-0412 | HIGH 7.2 | cisco content_services_switch_11050 Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode. | 0.4% | — |
| CVE-2001-0349 | HIGH 7.2 | microsoft windows_2000 Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program wi | 1.9% | — |
| CVE-2001-0344 | HIGH 7.2 | microsoft sql_server An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account. | 1.9% | — |
| CVE-2001-0281 | HIGH 7.2 | microsoft windows_nt Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges. | 4.8% | — |
| CVE-2001-0048 | HIGH 7.2 | microsoft windows_2000 The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Rest | 2.0% | — |
| CVE-2001-0016 | HIGH 7.2 | microsoft windows_nt NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access. | 2.1% | — |
| CVE-2001-0015 | HIGH 7.2 | microsoft windows_2000 Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process. | 3.2% | — |
| CVE-2000-0777 | HIGH 7.2 | microsoft money The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability. | 1.5% | — |
| CVE-2000-0420 | HIGH 7.2 | microsoft windows_2000 The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data. | 1.5% | — |
| CVE-2000-0325 | HIGH 7.2 | microsoft jet The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability. | 3.7% | — |
| CVE-2000-0298 | HIGH 7.2 | microsoft windows_2000 The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories. | 1.7% | — |
| CVE-2000-0277 | HIGH 7.2 | microsoft excel Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability. | 1.6% | — |
| CVE-2000-0259 | HIGH 7.2 | microsoft terminal_server The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users. | 1.5% | — |
| CVE-2000-0199 | HIGH 7.2 | microsoft sql_server When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password. | 1.5% | — |
| CVE-2000-0155 | HIGH 7.2 | microsoft windows_95 Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive. | 3.9% | — |
| CVE-2000-0100 | HIGH 7.2 | microsoft systems_management_server The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program. | 2.8% | — |
| CVE-2000-0088 | HIGH 7.2 | microsoft office Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability. | 1.9% | — |
| CVE-2000-0070 | HIGH 7.2 | microsoft windows_nt NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC Port Request." | 2.3% | — |
| CVE-1999-1556 | HIGH 7.2 | microsoft sql_server Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value. | 1.7% | — |
| CVE-1999-1442 | HIGH 7.2 | linux linux_kernel Bug in AMD K6 processor on Linux 2.0.x and 2.1.x kernels allows local users to cause a denial of service (crash) via a particular sequence of instructions, possibly related to accessing addresses outside of segments. | 0.9% | — |
| CVE-1999-1370 | HIGH 7.2 | microsoft internet_explorer The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prev | 1.3% | — |
| CVE-1999-1365 | HIGH 7.2 | microsoft windows_nt Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privil | 2.8% | — |
| CVE-1999-1276 | HIGH 7.2 | debian debian_linux fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device. | 0.3% | — |
| CVE-1999-1166 | HIGH 7.2 | linux linux_kernel Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory. | 1.0% | — |
| CVE-1999-0899 | HIGH 7.2 | microsoft windows_nt The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider. | 3.2% | — |