56.794 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.794 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2005-0738 | MED 5.0 | microsoft exchange_server Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang a | 4.5% | — |
| CVE-2005-0688 | MED 5.0 | microsoft windows_2003_server Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Lan | 47.4% | — |
| CVE-2005-0600 | MED 5.0 | cisco application_and_content_networking_software Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded. | 1.6% | — |
| CVE-2005-0599 | MED 5.0 | cisco application_and_content_networking_software Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, or 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (CPU consumption) via malformed IP packets. | 1.6% | — |
| CVE-2005-0598 | MED 5.0 | cisco application_and_content_networking_software The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets. | 3.2% | — |
| CVE-2005-0597 | MED 5.0 | cisco application_and_content_networking_software Cisco devices running Application and Content Networking System (ACNS) 5.0 before 5.0.17.6 and 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (process restart) via a "crafted TCP connection." | 2.7% | — |
| CVE-2005-0500 | MED 5.0 | microsoft ie Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in a titlebar for a script-initiated popup window, which could facilitate phishing attacks. | 10.7% | — |
| CVE-2005-0488 | MED 5.0 | microsoft telnet_client Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command. | 17.1% | — |
| CVE-2005-0360 | MED 5.0 | microsoft log_sink_class_activex_control The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files. | 12.3% | — |
| CVE-2005-0356 | MED 5.0 | alaxala alaxala_networks Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host t | 82.8% | — |
| CVE-2005-0196 | MED 5.0 | cisco ios Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, allows remote attackers to cause a denial of service (device reload) via a malformed BGP packet. | 4.1% | — |
| CVE-2005-0195 | MED 5.0 | cisco ios Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart) via a crafted IPv6 packet. | 3.7% | — |
| CVE-2005-0186 | MED 5.0 | cisco ios Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet to t | 2.6% | — |
| CVE-2005-0176 | MED 5.0 | linux linux_kernel The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released. | 2.2% | — |
| CVE-2005-0108 | MED 5.0 | apache mod_auth_radius Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument. | 3.4% | — |
| CVE-2004-2680 | MED 5.0 | apache mod_python mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory. | 4.3% | — |
| CVE-2004-2482 | MED 5.0 | microsoft outlook Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically d | 12.8% | — |
| CVE-2004-2434 | MED 5.0 | microsoft ie Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Expl | 32.8% | — |
| CVE-2004-2307 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 6.0.2600 on Windows XP allows remote attackers to cause a denial of service (browser crash) via a shell: URI with double backslashes (\\) in an HTML tag such as IFRAME or A. | 14.5% | — |
| CVE-2004-2179 | MED 5.0 | microsoft frontpage asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values. | 12.0% | — |
| CVE-2004-2137 | MED 5.0 | microsoft outlook_express Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive info | 26.1% | — |
| CVE-2004-2091 | MED 5.0 | microsoft baseline_security_analyzer Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security. | 3.2% | — |
| CVE-2004-2090 | MED 5.0 | microsoft ie Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist. | 16.0% | — |
| CVE-2004-1775 | MED 5.0 | cisco catos Cisco VACM (View-based Access Control MIB) for Catalyst Operating Software (CatOS) 5.5 and 6.1 and IOS 12.0 and 12.1 allows remote attackers to read and modify device configuration via the read-write community string. | 1.7% | — |
| CVE-2004-1766 | MED 5.0 | The default installation of NetScreen-Security Manager before Feature Pack 1 does not enable encryption for communication with devices running ScreenOS 5.0, which allows remote attackers to obtain sensitive information via sniffing. | 1.7% | — |