56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.831 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-1999-1225 | MED 5.0 | digital ultrix rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not | 1.8% | — |
| CVE-1999-1223 | MED 5.0 | microsoft internet_information_server IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters. | 23.1% | — |
| CVE-1999-1222 | MED 5.0 | microsoft windows_nt Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup. | 5.0% | — |
| CVE-1999-1201 | MED 5.0 | microsoft windows_95 Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a p | 13.9% | — |
| CVE-1999-1164 | MED 5.0 | microsoft outlook Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang. | 13.3% | — |
| CVE-1999-1157 | MED 5.0 | microsoft windows_nt Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface. | 13.3% | — |
| CVE-1999-1148 | MED 5.0 | microsoft internet_information_server FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time. | 17.3% | — |
| CVE-1999-1132 | MED 5.0 | microsoft windows_nt Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs. | 18.3% | — |
| CVE-1999-1110 | MED 5.0 | microsoft internet_explorer Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client. | 9.8% | — |
| CVE-1999-1105 | MED 5.0 | microsoft windows_95 Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive. | 21.7% | — |
| CVE-1999-1052 | MED 5.0 | microsoft frontpage Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users. | 14.3% | — |
| CVE-1999-1043 | MED 5.0 | microsoft exchange_server Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error). | 13.3% | — |
| CVE-1999-1035 | MED 5.0 | microsoft internet_information_server IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability. | 17.5% | — |
| CVE-1999-1033 | MED 5.0 | microsoft outlook_express Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang. | 17.5% | — |
| CVE-1999-1016 | MED 5.0 | microsoft frontpage Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML f | 7.7% | — |
| CVE-1999-1000 | MED 5.0 | cisco cache_engine The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics. | 2.0% | — |
| CVE-1999-0998 | MED 5.0 | cisco cache_engine Cisco Cache Engine allows an attacker to replace content in the cache. | 1.3% | — |
| CVE-1999-0994 | MED 5.0 | microsoft windows_nt Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords. | 7.2% | — |
| CVE-1999-0986 | MED 5.0 | debian debian_linux The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option. | 4.3% | — |
| CVE-1999-0980 | MED 5.0 | microsoft windows_nt Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request. | 23.2% | — |
| CVE-1999-0969 | MED 5.0 | microsoft windows_nt The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork. | 13.5% | — |
| CVE-1999-0945 | MED 5.0 | microsoft exchange_server Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands. | 19.5% | — |
| CVE-1999-0910 | MED 5.0 | microsoft commercial_internet_system Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user. | 5.8% | — |
| CVE-1999-0891 | MED 5.0 | microsoft internet_explorer The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect. | 42.6% | — |
| CVE-1999-0867 | MED 5.0 | microsoft commercial_internet_system Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. | 21.5% | — |