58.493 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.493 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2005-1942 | HIGH 7.5 | cisco catalyst Cisco switches that support 802.1x security allow remote attackers to bypass port security and gain access to the VLAN via spoofed Cisco Discovery Protocol (CDP) messages. | 1.6% | — |
| CVE-2005-1935 | HIGH 7.5 | microsoft windows_2000 Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the function to o | 26.6% | — |
| CVE-2005-1891 | HIGH 7.5 | aol aim The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable. | 2.3% | — |
| CVE-2005-1837 | HIGH 7.5 | fortinet fortinet_firewall Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges. | 1.1% | — |
| CVE-2005-1574 | HIGH 7.5 | microsoft windows_media_player Windows Media Player 9 and 10, in certain cases, allows content protected by Windows Media Digital Rights Management (WMDRM) to redirect the user to a web site to obtain a license, even when the "Acquire licenses automatically for protected content" setting is | 5.1% | — |
| CVE-2005-1517 | HIGH 7.5 | cisco firewall_services_module Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs). | 1.2% | — |
| CVE-2005-1344 | HIGH 7.5 | apache http_server Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escala | 29.1% | — |
| CVE-2005-1219 | HIGH 7.5 | microsoft image_color_management Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags. | 49.9% | — |
| CVE-2005-1216 | HIGH 7.5 | microsoft isa_server Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter. | 25.8% | — |
| CVE-2005-1215 | HIGH 7.5 | microsoft isa_server Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers. | 19.0% | — |
| CVE-2005-1213 | HIGH 7.5 | microsoft outlook_express Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field. | 74.0% | — |
| CVE-2005-1212 | HIGH 7.5 | microsoft windows_2000 Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field. | 24.9% | — |
| CVE-2005-1206 | HIGH 7.5 | microsoft windows_2000 Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability." | 59.4% | — |
| CVE-2005-1058 | HIGH 7.5 | cisco ios Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and m | 1.4% | — |
| CVE-2005-1057 | HIGH 7.5 | cisco ios Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet." | 1.4% | — |
| CVE-2005-0944 | HIGH 7.5 | microsoft jet Unknown vulnerability in Microsoft Jet DB engine (msjet40.dll) 4.00.8618.0, related to insufficient data validation, allows remote attackers to execute arbitrary code via a crafted mdb file. | 34.0% | — |
| CVE-2005-0821 | HIGH 7.5 | Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and mouse. | 1.3% | — |
| CVE-2005-0612 | HIGH 7.5 | cisco ipvc-3510-mcu Cisco IP/VC Videoconferencing System 3510, 3520, 3525 and 3530 contain hard-coded default SNMP community strings, which allows remote attackers to gain access, cause a denial of service, and modify configuration. | 1.5% | — |
| CVE-2005-0601 | HIGH 7.5 | cisco application_and_content_networking_software Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, 5.1, or 5.2 use a default password when the setup dialog has not been run, which allows remote attackers to gain access. | 1.6% | — |
| CVE-2005-0564 | HIGH 7.5 | microsoft word Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information. | 25.7% | — |
| CVE-2005-0562 | HIGH 7.5 | microsoft msn_messenger GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width. | 23.2% | — |
| CVE-2005-0560 | HIGH 7.5 | microsoft exchange_server Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port. | 69.5% | — |
| CVE-2005-0555 | HIGH 7.5 | microsoft internet_explorer Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability." | 58.4% | — |
| CVE-2005-0554 | HIGH 7.5 | microsoft internet_explorer Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerabili | 57.9% | — |
| CVE-2005-0416 | HIGH 7.5 | microsoft windows_2000 The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to execute arbitrary code via the AnimationHeaderBlock length field, which leads to a stack-based buffer over | 41.0% | — |