58.493 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.493 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2005-4499 | HIGH 7.5 | cisco adaptive_security_appliance_software The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allow | 2.6% | — |
| CVE-2005-3803 | HIGH 7.5 | cisco unified_wireless_ip_phone_7920_firmware Cisco IP Phone (VoIP) 7920 1.0(8) contains certain hard-coded ("fixed") public and private SNMP community strings that cannot be changed, which allows remote attackers to obtain sensitive information. | 2.1% | — |
| CVE-2005-3733 | HIGH 7.5 | juniper junos_e The Internet Key Exchange version 1 (IKEv1) implementation in Juniper JUNOS and JUNOSe software for M, T, and J-series routers before release 6.4, and E-series routers before 7-1-0, allows remote attackers to cause a denial of service and possibly execute arbi | 5.4% | — |
| CVE-2005-3652 | HIGH 7.5 | citrix ica_program_neighborhood_client Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response. | 16.0% | — |
| CVE-2005-3483 | HIGH 7.5 | graphon go-global Buffer overflow in GO-Global for Windows 3.1.0.3270 and earlier allows remote attackers to execute arbitrary code via a data block that is longer than the specified data block size. | 7.4% | — |
| CVE-2005-3176 | HIGH 7.5 | microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection. | 3.9% | — |
| CVE-2005-3168 | HIGH 7.5 | microsoft windows_2000 The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less sec | 3.8% | — |
| CVE-2005-3134 | HIGH 7.5 | citrix metaframe Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName). | 2.1% | — |
| CVE-2005-3058 | HIGH 7.5 | fortinet fortigate Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with | 3.1% | — |
| CVE-2005-2841 | HIGH 7.5 | cisco ios Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH and 12.2ZL, 12.3 and 12.3T, and 12.4 and 12.4T allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted user authen | 14.1% | — |
| CVE-2005-2831 | HIGH 7.5 | microsoft ie Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use withi | 30.1% | — |
| CVE-2005-2801 | HIGH 7.5 | linux linux_kernel xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied. | 3.4% | — |
| CVE-2005-2631 | HIGH 7.5 | cisco network_admission_control_manager_and_server_system_software Cisco Clean Access (CCA) 3.3.0 to 3.3.9, 3.4.0 to 3.4.5, and 3.5.0 to 3.5.3 does not properly authenticate users when invoking API methods, which could allow remote attackers to bypass security checks, change the assigned role of a user, or disconnect users. | 1.6% | — |
| CVE-2005-2500 | HIGH 7.5 | linux linux_kernel Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12, as used in SuSE Linux Enterprise Server 9, might allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted XDR data for the nfsacl proto | 4.7% | — |
| CVE-2005-2308 | HIGH 7.5 | microsoft ie The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via certain crafted JPEG images, as demonstrated using (1) mov_fencepost.jpg, (2) cmp_fencepost. | 17.4% | — |
| CVE-2005-2245 | HIGH 7.5 | f5 tmos Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors, possibly involving NATIVE ciphers. | 1.4% | — |
| CVE-2005-2181 | HIGH 7.5 | cisco ip_phone_7940_firmware Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message. | 1.2% | — |
| CVE-2005-2127 | HIGH 7.5 | ati catalyst_driver Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use withi | 63.7% | — |
| CVE-2005-2123 | HIGH 7.5 | microsoft windows_2000 Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that | 61.5% | — |
| CVE-2005-2105 | HIGH 7.5 | cisco ios Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, via a long username. | 2.6% | — |
| CVE-2005-1989 | HIGH 7.5 | microsoft ie Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability". | 45.7% | — |
| CVE-2005-1987 | HIGH 7.5 | microsoft exchange_server Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using | 44.5% | — |
| CVE-2005-1985 | HIGH 7.5 | microsoft windows_2000 The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages. | 37.3% | — |
| CVE-2005-1984 | HIGH 7.5 | microsoft windows_2000 Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message. | 55.3% | — |
| CVE-2005-1978 | HIGH 7.5 | microsoft windows_2000 COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code. | 53.4% | — |