56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.571 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-1999-1376 | HIGH 10.0 | microsoft internet_information_server Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands. | 24.0% | — |
| CVE-1999-1293 | HIGH 10.0 | apache http_server mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core. | 4.0% | — |
| CVE-1999-1241 | HIGH 10.0 | microsoft internet_explorer Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object. | 14.4% | — |
| CVE-1999-1237 | HIGH 10.0 | apache http_server Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified meth | 8.2% | — |
| CVE-1999-1199 | HIGH 10.0 | apache http_server Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability. | 7.6% | — |
| CVE-1999-1011 | HIGH 10.0 | microsoft data_access_components The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands. | 77.1% | — |
| CVE-1999-0987 | HIGH 10.0 | microsoft windows_nt Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name. | 4.9% | — |
| CVE-1999-0967 | HIGH 10.0 | microsoft internet_explorer Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol. | 7.0% | — |
| CVE-1999-0926 | HIGH 10.0 | apache http_server Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. | 9.4% | — |
| CVE-1999-0876 | HIGH 10.0 | microsoft ie Buffer overflow in Internet Explorer 4.0 via EMBED tag. | 5.7% | — |
| CVE-1999-0874 | HIGH 10.0 | microsoft internet_information_server Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions. | 74.7% | — |
| CVE-1999-0775 | HIGH 10.0 | cisco ios Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list. | 3.1% | — |
| CVE-1999-0702 | HIGH 10.0 | microsoft internet_explorer Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability. | 24.4% | — |
| CVE-1999-0590 | HIGH 10.0 | apple macos A system does not present an appropriate legal message or warning to a user who is accessing it. | 6.0% | — |
| CVE-1999-0581 | HIGH 10.0 | microsoft windows_nt The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. | 6.7% | — |
| CVE-1999-0579 | HIGH 10.0 | microsoft windows_nt A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. | 6.1% | — |
| CVE-1999-0577 | HIGH 10.0 | microsoft windows_nt A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. | 6.1% | — |
| CVE-1999-0570 | HIGH 10.0 | microsoft windows_nt Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. | 6.0% | — |
| CVE-1999-0560 | HIGH 10.0 | microsoft windows_nt A system-critical Windows NT file or directory has inappropriate permissions. | 5.9% | — |
| CVE-1999-0535 | HIGH 10.0 | microsoft windows_2000 A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness. | 6.0% | — |
| CVE-1999-0489 | HIGH 10.0 | microsoft windows_nt MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013. | 12.4% | — |
| CVE-1999-0461 | HIGH 10.0 | linux linux_kernel Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address. | 3.2% | — |
| CVE-1999-0407 | HIGH 10.0 | microsoft internet_information_server By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. | 5.1% | — |
| CVE-1999-0385 | HIGH 10.0 | microsoft exchange_server The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. | 18.2% | — |
| CVE-1999-0364 | HIGH 10.0 | fms_inc. total_vb_sourcebook Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data. | 5.2% | — |