56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.831 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2000-0753 | MED 5.0 | microsoft outlook The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files. | 5.2% | — |
| CVE-2000-0742 | MED 5.0 | microsoft windows_95 The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability. | 18.8% | — |
| CVE-2000-0710 | MED 5.0 | microsoft frontpage The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name. | 26.4% | — |
| CVE-2000-0709 | MED 5.0 | microsoft frontpage The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name. | 25.4% | — |
| CVE-2000-0700 | MED 5.0 | cisco gigabit_switch_router_12008 Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the i | 1.7% | — |
| CVE-2000-0673 | MED 5.0 | microsoft windows_2000 The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability. | 32.9% | — |
| CVE-2000-0672 | MED 5.0 | apache tomcat The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory. | 9.8% | — |
| CVE-2000-0662 | MED 5.0 | microsoft internet_explorer Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED). | 21.0% | — |
| CVE-2000-0653 | MED 5.0 | microsoft outlook_express Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability. | 27.1% | — |
| CVE-2000-0631 | MED 5.0 | microsoft internet_information_server An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability. | 24.9% | — |
| CVE-2000-0630 | MED 5.0 | microsoft internet_information_server IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability. | 68.4% | — |
| CVE-2000-0613 | MED 5.0 | cisco pix_firewall Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legitimate connections. | 9.2% | — |
| CVE-2000-0612 | MED 5.0 | microsoft windows_95 Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table. | 8.7% | — |
| CVE-2000-0581 | MED 5.0 | microsoft windows_2000 Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash. | 22.0% | — |
| CVE-2000-0580 | MED 5.0 | microsoft windows_2000 Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization. | 16.0% | — |
| CVE-2000-0567 | MED 5.0 | microsoft outlook Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability. | 32.3% | — |
| CVE-2000-0544 | MED 5.0 | microsoft windows_2000 Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length. | 17.8% | — |
| CVE-2000-0524 | MED 5.0 | microsoft exchange_server Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From. | 14.6% | — |
| CVE-2000-0505 | MED 5.0 | apache http_server The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters. | 46.7% | — |
| CVE-2000-0495 | MED 5.0 | microsoft windows_media_services Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder Request" vulnerability. | 32.3% | — |
| CVE-2000-0486 | MED 5.0 | cisco ios Buffer overflow in Cisco TACACS+ tac_plus server allows remote attackers to cause a denial of service via a malformed packet with a long length field. | 2.1% | — |
| CVE-2000-0416 | MED 5.0 | microsoft windows_2000 NTMail 5.x allows network users to bypass the NTMail proxy restrictions by redirecting their requests to NTMail's web configuration server. | 5.8% | — |
| CVE-2000-0415 | MED 5.0 | microsoft outlook Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name. | 6.1% | — |
| CVE-2000-0413 | MED 5.0 | microsoft frontpage The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the p | 43.9% | — |
| CVE-2000-0408 | MED 5.0 | microsoft internet_information_server IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability. | 58.0% | — |