56.664 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.664 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2000-0933 | MED 4.6 | microsoft windows_2000 The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recogniti | 2,2% | — |
| CVE-2000-0851 | MED 4.6 | microsoft windows_2000 Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the "Still Image Service Privilege Escalation" vulnerability. | 7,6% | — |
| CVE-2000-0790 | MED 4.6 | microsoft windows_2000 The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a defaul | 1,4% | — |
| CVE-2000-0737 | MED 4.6 | microsoft windows_2000 The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability. | 4,4% | — |
| CVE-2000-0663 | MED 4.6 | microsoft windows_2000 The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, | 2,0% | — |
| CVE-2000-0654 | MED 4.6 | microsoft sql_server Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability. | 1,4% | — |
| CVE-2000-0637 | MED 4.6 | microsoft excel Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability. | 2,4% | — |
| CVE-2000-0603 | MED 4.6 | microsoft sql_server Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the "Stored Procedure Permissions" vulnerability. | 2,3% | — |
| CVE-2000-0475 | MED 4.6 | microsoft windows_2000 Windows 2000 allows a local user process to access another user's desktop within the same windows station, aka the "Desktop Separation" vulnerability. | 1,9% | — |
| CVE-2000-0267 | MED 4.6 | cisco catos Cisco Catalyst 5.4.x allows a user to gain access to the "enable" mode without a password. | 0,4% | — |
| CVE-2000-0197 | MED 4.6 | microsoft windows_nt The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file. | 1,6% | — |
| CVE-1999-1431 | MED 4.6 | microsoft zero_administration_kit ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Win | 9,7% | — |
| CVE-1999-1367 | MED 4.6 | microsoft internet_explorer Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users. | 1,2% | — |
| CVE-1999-1358 | MED 4.6 | microsoft windows_2000 When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the po | 1,4% | — |
| CVE-1999-1352 | MED 4.6 | linux linux_kernel mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges. | 0,4% | — |
| CVE-1999-1341 | MED 4.6 | linux linux_kernel Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices. | 0,4% | — |
| CVE-1999-1322 | MED 4.6 | broadcom arcserve_backup The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext. | 1,5% | — |
| CVE-1999-1317 | MED 4.6 | microsoft windows_nt Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device. | 1,8% | — |
| CVE-1999-1235 | MED 4.6 | microsoft internet_explorer Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to | 2,7% | — |
| CVE-1999-1217 | MED 4.6 | microsoft windows_nt The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories. | 2,2% | — |
| CVE-1999-1104 | MED 4.6 | microsoft windows_95 Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords. | 1,0% | — |
| CVE-1999-1084 | MED 4.6 | microsoft windows_nt The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash. | 3,5% | — |
| CVE-1999-0975 | MED 4.6 | microsoft windows_95 The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed. | 2,7% | — |
| CVE-1999-0824 | MED 4.6 | microsoft windows_nt A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users. | 1,2% | — |
| CVE-1999-0794 | MED 4.6 | microsoft excel Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file. | 1,5% | — |