56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.831 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2000-0404 | MED 5.0 | microsoft terminal_server The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability. | 17.9% | — |
| CVE-2000-0403 | MED 5.0 | microsoft windows_nt The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the "HostAnnouncement Flooding" or "HostAnnouncement Frame" vulne | 17.9% | — |
| CVE-2000-0377 | MED 5.0 | microsoft windows_nt The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability. | 19.2% | — |
| CVE-2000-0347 | MED 5.0 | microsoft windows_95 Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name. | 17.6% | — |
| CVE-2000-0344 | MED 5.0 | linux linux_kernel The knfsd NFS server in Linux kernel 2.2.x allows remote attackers to cause a denial of service via a negative size value. | 1.9% | — |
| CVE-2000-0331 | MED 5.0 | microsoft terminal_server Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability. | 7.5% | — |
| CVE-2000-0328 | MED 5.0 | microsoft windows_nt Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking. | 24.7% | — |
| CVE-2000-0304 | MED 5.0 | microsoft internet_information_server Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability. | 29.3% | — |
| CVE-2000-0302 | MED 5.0 | microsoft index_server Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL. | 78.6% | — |
| CVE-2000-0289 | MED 5.0 | debian debian_linux IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection. | 2.6% | — |
| CVE-2000-0268 | MED 5.0 | cisco 3660_router Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON option to the Telnet daemon before it is ready to accept it, which causes the system to reboot. | 1.7% | — |
| CVE-2000-0246 | MED 5.0 | microsoft commercial_internet_system IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability. | 80.0% | — |
| CVE-2000-0228 | MED 5.0 | microsoft windows_media_rights_manager Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the "Malformed Media License Request" Vulnerability. | 13.7% | — |
| CVE-2000-0226 | MED 5.0 | microsoft internet_information_server IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the "Chunked Transfer Encoding Buffer Overflow Vulnerability." | 6.8% | — |
| CVE-2000-0216 | MED 5.0 | microsoft exchange_server Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a l | 5.1% | — |
| CVE-2000-0211 | MED 5.0 | microsoft windows_media_services The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerability. | 21.3% | — |
| CVE-2000-0168 | MED 5.0 | microsoft windows_95 Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability. | 19.6% | — |
| CVE-2000-0153 | MED 5.0 | microsoft frontpage FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack. | 13.7% | — |
| CVE-2000-0126 | MED 5.0 | microsoft internet_information_server Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack. | 45.7% | — |
| CVE-2000-0122 | MED 5.0 | microsoft frontpage Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program. | 21.5% | — |
| CVE-2000-0115 | MED 5.0 | microsoft internet_information_server IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page. | 9.8% | — |
| CVE-2000-0114 | MED 5.0 | microsoft internet_information_server Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. | 47.6% | — |
| CVE-2000-0105 | MED 5.0 | microsoft outlook_express Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client. | 20.7% | — |
| CVE-2000-0098 | MED 5.0 | microsoft index_server Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist. | 48.5% | — |
| CVE-2000-0097 | MED 5.0 | microsoft index_server The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability. | 35.9% | — |