Vulnerability index

Browse CVEs

409 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Internet Explorer MEDIUM 6.5
CVE-2010-0488EPSS 29%

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypas…

Patch available
Fix from $1,600 2010-03-31
Visual C\+\+ MEDIUM 6.5
CVE-2009-2495EPSS 34%

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and…

Mitigation only
Fix from $1,600 2009-07-29
Internet Information Services HIGH 7.5
CVE-2003-1567EPSS 25%

The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the res…

No fix yet
Fix from $1,950 2009-01-15
Windows Live Messenger MEDIUM 5.0
CVE-2008-5828EPSS 14%

Microsoft Windows Live Messenger Client 8.5.1 and earlier, when MSN Protocol Version 15 (MSNP15) is used over a NAT session, allows remote attackers …

Fix: after 8.5.1
Fix from $1,600 2009-01-02
Windows Media Player HIGH 10.0
CVE-2008-3010EPSS 15%

Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP ad…

Mitigation only
Fix from $1,950 2008-12-10
Windows MEDIUM 5.0
CVE-2008-5112EPSS 18%

The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending…

No fix yet
Fix from $1,600 2008-11-17
Windows Messenger HIGH 10.0
CVE-2008-0082EPSS 34%

An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to cont…

Mitigation only
Fix from $1,950 2008-08-13
Windows Nt HIGH 7.8
CVE-2008-2246EPSS 32%

Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Se…

Patch available
Fix from $1,950 2008-08-13
Data Engine MEDIUM 5.0
CVE-2008-0085EPSS 11%

SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE…

Patch available
Fix from $1,600 2008-07-08
Isa Server MEDIUM 5.0
CVE-2007-4991EPSS 16%

The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitiv…

Patch available
Fix from $1,600 2007-09-21
.net Framework HIGH 7.8
CVE-2007-0042EPSS 76%

Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers…

Mitigation only
Fix from $1,950 2007-07-10
Exchange Server MEDIUM 6.0
CVE-2003-0904EPSS 8%

Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can…

Patch available
Fix from $1,600 2004-01-20
Ie MEDIUM 5.0
CVE-2003-1559EPSS 16%

Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, wh…

Mitigation only
Fix from $1,600 2003-12-31
Network Firmware MEDIUM 6.4
CVE-2002-2380EPSS 11%

NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented u…

Mitigation only
Fix from $1,600 2002-12-31
Internet Information Services MEDIUM 5.0
CVE-2002-1717EPSS 16%

Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1) /_vti_pvt/access.cnf, (2) /…

Mitigation only
Fix from $1,600 2002-12-31
Internet Information Services MEDIUM 5.0
CVE-2002-1718EPSS 14%

Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a Frontpage Server Extension (FPSE) file, as claim…

Mitigation only
Fix from $1,600 2002-12-31
Internet Information Server MEDIUM 5.0
CVE-2002-0419EPSS 38%

Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks …

No fix yet
Fix from $1,600 2002-08-12
Internet Information Server MEDIUM 5.0
CVE-1999-0348EPSS 11%

IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.

Mitigation only
Fix from $1,600 1999-01-27
Windows 2000 CRITICAL 9.1
CVE-1999-0511EPSS 7%

IP forwarding is enabled on a machine which is not a router or firewall.

Mitigation only
Fix from $2,300 1997-01-01