56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.569 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2001-0544 | LOW 2.1 | microsoft internet_information_services IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type table. | 2.3% | — |
| CVE-2001-0444 | LOW 2.1 | cisco cbos Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information. | 0.5% | — |
| CVE-2001-0373 | LOW 2.1 | microsoft windows_2000 The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information. | 2.3% | — |
| CVE-2001-0351 | LOW 2.1 | microsoft windows_2000 Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service. | 1.8% | — |
| CVE-2001-0261 | LOW 2.1 | microsoft windows_2000 Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files. | 2.3% | — |
| CVE-2001-0152 | LOW 2.1 | microsoft plus The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password information to a file, which allows local users to recover the passwords and read the compressed folders. | 8.9% | — |
| CVE-2001-0020 | LOW 2.1 | cisco arrowpoint Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack. | 0.5% | — |
| CVE-2001-0019 | LOW 2.1 | cisco arrowpoint Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands. | 0.3% | — |
| CVE-2000-1247 | LOW 2.1 | apache jserv The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI. | 0.6% | — |
| CVE-2000-1083 | LOW 2.1 | microsoft data_engine The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacke | 5.5% | — |
| CVE-2000-0771 | LOW 2.1 | microsoft windows_2000 Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability. | 1.5% | — |
| CVE-2000-0485 | LOW 2.1 | microsoft sql_server Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability. | 2.4% | — |
| CVE-2000-0402 | LOW 2.1 | microsoft sql_server The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability. | 90.6% | — |
| CVE-2000-0368 | LOW 2.1 | cisco ios Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data. | 0.4% | — |
| CVE-2000-0345 | LOW 2.1 | cisco ios The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command. | 0.5% | — |
| CVE-2000-0311 | LOW 2.1 | microsoft windows_2000 The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability. | 1.4% | — |
| CVE-2000-0232 | LOW 2.1 | microsoft terminal_server Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request. | 3.5% | — |
| CVE-2000-0227 | LOW 2.1 | linux linux_kernel The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which allows local users to cause a denial of service by requesting a large number of sockets. | 0.8% | — |
| CVE-2000-0167 | LOW 2.1 | microsoft internet_information_server IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory. | 2.7% | — |
| CVE-2000-0129 | LOW 2.1 | microsoft windows_95 Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file. | 3.8% | — |
| CVE-2000-0089 | LOW 2.1 | microsoft windows_nt The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability. | 2.3% | — |
| CVE-1999-1538 | LOW 2.1 | microsoft internet_information_server When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password | 25.5% | — |
| CVE-1999-1452 | LOW 2.1 | microsoft windows_nt GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt. | 5.7% | — |
| CVE-1999-1446 | LOW 2.1 | microsoft internet_explorer Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user br | 2.0% | — |
| CVE-1999-1441 | LOW 2.1 | linux linux_kernel Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial of service by sending SIGIO to processes that do not catch it. | 0.7% | — |