56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.831 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2000-0082 | MED 5.0 | microsoft webtv WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML. | 14.5% | — |
| CVE-2000-0073 | MED 5.0 | microsoft windows_2000 Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word. | 20.7% | — |
| CVE-2000-0071 | MED 5.0 | microsoft internet_information_server IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. | 28.1% | — |
| CVE-2000-0036 | MED 5.0 | microsoft ie Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability. | 3.9% | — |
| CVE-2000-0025 | MED 5.0 | microsoft internet_information_server IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability. | 34.9% | — |
| CVE-1999-1581 | MED 5.0 | microsoft windows_nt Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large number of SNMP packets with Object Identifiers (OIDs) that | 20.6% | — |
| CVE-1999-1579 | MED 5.0 | microsoft windows_nt The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on the targe | 21.8% | — |
| CVE-1999-1550 | MED 5.0 | f5 tmos bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter. | 8.6% | — |
| CVE-1999-1544 | MED 5.0 | microsoft internet_information_server Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command. | 13.6% | — |
| CVE-1999-1537 | MED 5.0 | microsoft internet_information_server IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause | 8.5% | — |
| CVE-1999-1520 | MED 5.0 | microsoft site_server A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information. | 11.7% | — |
| CVE-1999-1478 | MED 5.0 | microsoft internet_information_server The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character. | 18.3% | — |
| CVE-1999-1473 | MED 5.0 | microsoft internet_explorer When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue." | 7.4% | — |
| CVE-1999-1472 | MED 5.0 | microsoft internet_explorer Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue. | 17.2% | — |
| CVE-1999-1463 | MED 5.0 | microsoft windows_nt Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session. | 16.3% | — |
| CVE-1999-1451 | MED 5.0 | microsoft internet_information_server The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files. | 17.7% | — |
| CVE-1999-1447 | MED 5.0 | microsoft internet_explorer Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag. | 13.5% | — |
| CVE-1999-1412 | MED 5.0 | apache http_server A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes. | 35.3% | — |
| CVE-1999-1387 | MED 5.0 | microsoft windows_nt Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25. | 20.8% | — |
| CVE-1999-1375 | MED 5.0 | microsoft internet_information_server FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. | 30.5% | — |
| CVE-1999-1339 | MED 5.0 | freebsd freebsd Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command. | 2.6% | — |
| CVE-1999-1291 | MED 5.0 | microsoft windows_95 TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then | 13.5% | — |
| CVE-1999-1279 | MED 5.0 | microsoft sna_server An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU. | 5.8% | — |
| CVE-1999-1254 | MED 5.0 | microsoft windows_95 Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables. | 13.3% | — |
| CVE-1999-1234 | MED 5.0 | microsoft windows_nt LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo. | 13.5% | — |