57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2004-0940 | HIGH 7.8 | apache http_server Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error. | 4.8% | — |
| CVE-2004-0747 | HIGH 7.8 | apache http_server Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables. | 1.6% | — |
| CVE-2004-0213 | HIGH 7.8 | microsoft windows_2000 Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhl | 20.1% | — |
| CVE-2004-0210 | HIGH 7.8 | microsoft interix The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow. | 7.2% | |
| CVE-2003-1477 | HIGH 7.8 | clearswift mailsweeper_for_smtp MAILsweeper for SMTP 4.3.6 and 4.3.7 allows remote attackers to cause a denial of service (CPU consumption) via a PowerPoint attachment that either (1) is corrupt or (2) contains "embedded objects." | 1.6% | — |
| CVE-2003-1448 | HIGH 7.8 | microsoft windows_2000 Memory leak in the Windows 2000 kernel allows remote attackers to cause a denial of service (SMB request hang) via a NetBIOS continuation packet. | 15.4% | — |
| CVE-2003-1048 | HIGH 7.8 | microsoft internet_explorer Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image. | 26.6% | — |
| CVE-2003-1003 | HIGH 7.8 | cisco pix_firewall Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set. | 1.4% | — |
| CVE-2003-0567 | HIGH 7.8 | cisco ios Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full. | 16.6% | — |
| CVE-2002-2379 | HIGH 7.8 | cisco as5350 Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of service (crash) via a port scan, possibly due to an ssh bug. NOTE: this issue could not be reproduced by the vendor | 5.9% | — |
| CVE-2002-2315 | HIGH 7.8 | cisco ios Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumption) via spoofed ICMP redirect packets to the router. | 9.6% | — |
| CVE-2002-2272 | HIGH 7.8 | apache http_server Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values. | 9.7% | — |
| CVE-2002-2239 | HIGH 7.8 | cisco ios The Cisco Optical Service Module (OSM) for the Catalyst 6500 and 7600 series running Cisco IOS 12.1(8)E through 12.1(13.4)E allows remote attackers to cause a denial of service (hang) via a malformed packet. | 1.6% | — |
| CVE-2002-2208 | HIGH 7.8 | cisco ios Extended Interior Gateway Routing Protocol (EIGRP), as implemented in Cisco IOS 11.3 through 12.2 and other products, allows remote attackers to cause a denial of service (flood) by sending a large number of spoofed EIGRP neighbor announcements, which results | 4.3% | — |
| CVE-2002-1844 | HIGH 7.8 | microsoft windows_media_player Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privileges. | 1.2% | — |
| CVE-2002-0969 | HIGH 7.8 | oracle mysql Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Con | 1.4% | — |
| CVE-2002-0367 | HIGH 7.8 | microsoft windows_2000 smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstr | 4.9% | |
| CVE-2002-0051 | HIGH 7.8 | microsoft windows_2000 Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access. | 0.8% | — |
| CVE-2001-1238 | HIGH 7.8 | microsoft windows_2000 Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be s | 1.2% | — |
| CVE-2001-0041 | HIGH 7.8 | cisco catos Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts. | 12.1% | — |
| CVE-2000-0305 | HIGH 7.8 | be beos Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability. | 38.4% | — |
| CVE-1999-0995 | HIGH 7.8 | microsoft windows_nt Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request." | 21.8% | — |
| CVE-1999-0918 | HIGH 7.8 | microsoft windows_2000 Denial of service in various Windows systems via malformed, fragmented IGMP packets. | 26.4% | — |
| CVE-1999-0728 | HIGH 7.8 | microsoft windows_nt A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them. | 5.8% | — |
| CVE-1999-0726 | HIGH 7.8 | microsoft windows_2000 An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header. | 8.5% | — |