56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.831 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-1999-0858 | MED 5.0 | microsoft internet_explorer Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server. | 13.4% | — |
| CVE-1999-0843 | MED 5.0 | cisco router Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port. | 1.4% | — |
| CVE-1999-0819 | MED 5.0 | microsoft windows_2000 NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it. | 14.8% | — |
| CVE-1999-0815 | MED 5.0 | microsoft windows_nt Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries. | 17.9% | — |
| CVE-1999-0804 | MED 5.0 | debian debian_linux Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths. | 5.6% | — |
| CVE-1999-0755 | MED 5.0 | microsoft windows_2000 Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option. | 15.0% | — |
| CVE-1999-0739 | MED 5.0 | microsoft internet_information_server The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | 28.7% | — |
| CVE-1999-0738 | MED 5.0 | microsoft internet_information_server The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | 28.7% | — |
| CVE-1999-0737 | MED 5.0 | microsoft internet_information_server The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | 28.1% | — |
| CVE-1999-0736 | MED 5.0 | microsoft internet_information_server The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | 44.8% | — |
| CVE-1999-0682 | MED 5.0 | microsoft exchange_server Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled. | 26.1% | — |
| CVE-1999-0681 | MED 5.0 | microsoft frontpage Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL. | 20.5% | — |
| CVE-1999-0680 | MED 5.0 | microsoft terminal_server Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service. | 5.7% | — |
| CVE-1999-0678 | MED 5.0 | apache http_server A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server. | 31.4% | — |
| CVE-1999-0656 | MED 5.0 | linux linux_kernel The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names. | 1.6% | — |
| CVE-1999-0628 | MED 5.0 | freebsd freebsd The rwho/rwhod service is running, which exposes machine status and user information. | 1.5% | — |
| CVE-1999-0582 | MED 5.0 | microsoft windows_2000 A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. | 6.3% | — |
| CVE-1999-0513 | MED 5.0 | digital unix ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service. | 70.5% | — |
| CVE-1999-0469 | MED 5.0 | microsoft internet_explorer Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client. | 17.2% | — |
| CVE-1999-0453 | MED 5.0 | cisco router An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP). | 1.4% | — |
| CVE-1999-0448 | MED 5.0 | microsoft internet_information_server IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. | 24.6% | — |
| CVE-1999-0445 | MED 5.0 | cisco ios In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters. | 1.1% | — |
| CVE-1999-0444 | MED 5.0 | microsoft windows_95 Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files. | 16.2% | — |
| CVE-1999-0431 | MED 5.0 | linux linux_kernel Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service. | 6.6% | — |
| CVE-1999-0430 | MED 5.0 | cisco catalyst_12xx_supervisor_software Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload. | 1.8% | — |