58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2001-0154 | HIGH 7.5 | microsoft internet_explorer HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly. | 11.2% | — |
| CVE-2001-0153 | HIGH 7.5 | microsoft visual_basic Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands. | 12.4% | — |
| CVE-2001-0148 | HIGH 7.5 | microsoft windows_media_player The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability. | 26.8% | — |
| CVE-2001-0145 | HIGH 7.5 | microsoft outlook Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field. | 6.7% | — |
| CVE-2001-0056 | HIGH 7.5 | cisco broadband_operating_system The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection. | 1.4% | — |
| CVE-2001-0047 | HIGH 7.5 | microsoft windows_nt The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities. | 5.6% | — |
| CVE-2001-0002 | HIGH 7.5 | microsoft internet_explorer Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs. | 20.2% | — |
| CVE-2000-1149 | HIGH 7.5 | microsoft windows_nt Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the "Terminal Server Login Buffer Overflow" vulnerability. | 16.1% | — |
| CVE-2000-1139 | HIGH 7.5 | microsoft exchange_server The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability. | 5.0% | — |
| CVE-2000-1113 | HIGH 7.5 | microsoft windows_media_player Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the ".ASX Buffer Overrun" vulnerability. | 19.4% | — |
| CVE-2000-1104 | HIGH 7.5 | microsoft internet_information_server Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the | 5.6% | — |
| CVE-2000-1079 | HIGH 7.5 | microsoft windows_2000 Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram. | 15.9% | — |
| CVE-2000-1056 | HIGH 7.5 | cisco secure_access_control_server CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords. | 1.7% | — |
| CVE-2000-1022 | HIGH 7.5 | cisco pix_firewall_software The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands. | 7.1% | — |
| CVE-2000-0982 | HIGH 7.5 | microsoft internet_explorer Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credential | 12.6% | — |
| CVE-2000-0970 | HIGH 7.5 | microsoft internet_information_server IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vuln | 45.7% | — |
| CVE-2000-0955 | HIGH 7.5 | cisco virtual_central_office_4000 Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges. | 1.8% | — |
| CVE-2000-0886 | HIGH 7.5 | microsoft internet_information_server IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability. | 68.7% | — |
| CVE-2000-0885 | HIGH 7.5 | microsoft systems_management_server Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol P | 12.8% | — |
| CVE-2000-0884 | HIGH 7.5 | microsoft internet_information_server IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability. | 72.1% | — |
| CVE-2000-0834 | HIGH 7.5 | microsoft windows_2000 The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM | 39.6% | — |
| CVE-2000-0817 | HIGH 7.5 | microsoft network_monitor Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability. | 15.1% | — |
| CVE-2000-0746 | HIGH 7.5 | microsoft frontpage Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the cl | 10.1% | — |
| CVE-2000-0711 | HIGH 7.5 | microsoft virtual_machine Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice. | 33.5% | — |
| CVE-2000-0621 | HIGH 7.5 | microsoft outlook Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability. | 22.1% | — |