56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.831 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2001-0014 | MED 5.0 | microsoft windows_2000 Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability. | 13.3% | — |
| CVE-2001-0004 | MED 5.0 | microsoft internet_information_server IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .H | 28.2% | — |
| CVE-2001-0003 | MED 5.0 | microsoft office Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the | 7.4% | — |
| CVE-2000-1227 | MED 5.0 | microsoft windows_2000 Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back. | 13.0% | — |
| CVE-2000-1210 | MED 5.0 | apache tomcat Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp. | 3.5% | — |
| CVE-2000-1206 | MED 5.0 | apache http_server Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files. | 5.3% | — |
| CVE-2000-1204 | MED 5.0 | apache http_server Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root. | 10.5% | — |
| CVE-2000-1200 | MED 5.0 | microsoft windows_nt Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users. | 48.1% | — |
| CVE-2000-1111 | MED 5.0 | microsoft windows_2000 Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input. | 13.1% | — |
| CVE-2000-1090 | MED 5.0 | microsoft internet_information_server Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character. | 16.7% | — |
| CVE-2000-1039 | MED 5.0 | microsoft windows_95 Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the | 45.8% | — |
| CVE-2000-1027 | MED 5.0 | cisco pix_firewall_software Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established. | 3.5% | — |
| CVE-2000-1006 | MED 5.0 | microsoft exchange_server Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability. | 14.8% | — |
| CVE-2000-0984 | MED 5.0 | cisco ios The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string. | 4.3% | — |
| CVE-2000-0983 | MED 5.0 | microsoft netmeeting Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability. | 20.6% | — |
| CVE-2000-0980 | MED 5.0 | microsoft windows_95 NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network. | 13.2% | — |
| CVE-2000-0951 | MED 5.0 | microsoft internet_information_services A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search. | 44.1% | — |
| CVE-2000-0929 | MED 5.0 | microsoft windows_media_player Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability. | 14.4% | — |
| CVE-2000-0913 | MED 5.0 | apache http_server mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression. | 35.6% | — |
| CVE-2000-0869 | MED 5.0 | apache http_server The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method. | 50.9% | — |
| CVE-2000-0868 | MED 5.0 | apache http_server The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/. | 44.7% | — |
| CVE-2000-0858 | MED 5.0 | microsoft internet_information_server Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability. | 18.8% | — |
| CVE-2000-0830 | MED 5.0 | microsoft webtv annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP packet to ports 22701 through 22705. | 25.9% | — |
| CVE-2000-0778 | MED 5.0 | microsoft internet_information_services IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability. | 87.3% | — |
| CVE-2000-0756 | MED 5.0 | microsoft outlook Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service. | 5.1% | — |