56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.569 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2003-1582 | LOW 2.6 | microsoft internet_information_server Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by inject | 10.3% | — |
| CVE-2003-1581 | LOW 2.6 | apache http_server The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, r | 3.1% | — |
| CVE-2003-1306 | LOW 2.6 | Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in th | 1.3% | — |
| CVE-2003-1105 | LOW 2.6 | microsoft ie Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service (browser or Outlook Express crash) via HTML with certain input tags that are not properly rendered. | 17.7% | — |
| CVE-2003-0956 | LOW 2.6 | linux linux_kernel Multiple race conditions in the handling of O_DIRECT in Linux kernel prior to version 2.4.22 could cause stale data to be returned from the disk when handling sparse files, or cause incorrect data to be returned when a file is truncated as it is being read, wh | 0.3% | — |
| CVE-2002-1444 | LOW 2.6 | google toolbar The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect c | 13.5% | — |
| CVE-2002-1233 | LOW 2.6 | apache http_server A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on tempora | 0.6% | — |
| CVE-2002-0422 | LOW 2.6 | microsoft internet_information_services IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Mul | 42.3% | — |
| CVE-2001-1450 | LOW 2.6 | microsoft internet_explorer Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./". | 7.0% | — |
| CVE-2001-0807 | LOW 2.6 | microsoft internet_explorer Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file. | 7.0% | — |
| CVE-2001-0324 | LOW 2.6 | microsoft windows_2000 Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash. | 14.3% | — |
| CVE-2001-0092 | LOW 2.6 | microsoft internet_explorer A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability. | 12.2% | — |
| CVE-2001-0091 | LOW 2.6 | microsoft internet_explorer The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability. | 5.5% | — |
| CVE-2001-0089 | LOW 2.6 | microsoft internet_explorer Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability. | 14.5% | — |
| CVE-2000-1003 | LOW 2.6 | microsoft windows_95 NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash. | 12.5% | — |
| CVE-2000-0849 | LOW 2.6 | microsoft windows_media_services Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability. | 15.0% | — |
| CVE-2000-0768 | LOW 2.6 | microsoft ie A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability. | 9.5% | — |
| CVE-2000-0767 | LOW 2.6 | microsoft internet_explorer The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability. | 4.4% | — |
| CVE-2000-0649 | LOW 2.6 | microsoft internet_information_server IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined. | 76.6% | — |
| CVE-2000-0519 | LOW 2.6 | microsoft ie Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities. | 4.8% | — |
| CVE-2000-0518 | LOW 2.6 | microsoft ie Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities. | 4.8% | — |
| CVE-2000-0503 | LOW 2.6 | microsoft internet_explorer The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event. | 9.3% | — |
| CVE-2000-0439 | LOW 2.6 | microsoft internet_explorer Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability. | 6.3% | — |
| CVE-2000-0266 | LOW 2.6 | microsoft internet_explorer Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL. | 16.2% | — |
| CVE-2000-0132 | LOW 2.6 | microsoft virtual_machine Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function. | 19.0% | — |