Vulnerability index

Browse CVEs

203 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Internet Information Server HIGH 7.2
CVE-2008-0074EPSS 5%

Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors …

Mitigation only
Fix from $1,950 2008-02-12
Windows 2000 HIGH 7.2
CVE-2007-5352

Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 al…

Patch available
Fix from $1,950 2008-01-08
Windows Services For Unix MEDIUM 6.9
CVE-2007-3036

Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, …

Mitigation only
Fix from $1,600 2007-09-12
Internet Information Services HIGH 10.0
CVE-2007-2815EPSS 73%

The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configur…

Mitigation only
Fix from $1,950 2007-05-22
Windows MEDIUM 6.8
CVE-2007-2108EPSS 22%

Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers …

Mitigation only
Fix from $1,600 2007-04-18
Windows 2000 HIGH 7.2
CVE-2007-1206

The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows V…

Mitigation only
Fix from $1,950 2007-04-10
Windows 2003 Server HIGH 7.2
CVE-2006-5585

The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest wi…

Patch available
Fix from $1,950 2006-12-13
Office HIGH 7.2
CVE-2006-0008

The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, an…

Patch available
Fix from $1,950 2006-02-14
Ie HIGH 7.1
CVE-2005-4089EPSS 22%

Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @impor…

No fix yet
Fix from $1,950 2005-12-08
Outlook Express MEDIUM 5.8
CVE-2004-2694EPSS 9%

Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook co…

Mitigation only
Fix from $1,600 2004-12-31
Ie HIGH 9.3
CVE-2003-1026EPSS 39%

Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added…

Mitigation only
Fix from $1,950 2004-01-20
Outlook HIGH 8.8
CVE-2003-1378EPSS 16%

Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs vi…

No fix yet
Fix from $1,950 2003-12-31
Data Engine HIGH 7.2
CVE-2003-0230

Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka…

Mitigation only
Fix from $1,950 2003-08-27
Internet Explorer MEDIUM 6.4
CVE-2002-2311EPSS 10%

Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to…

No fix yet
Fix from $1,600 2002-12-31
Ie HIGH 7.2
CVE-1999-0839

Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.

Mitigation only
Fix from $1,950 1999-11-29
Windows Nt HIGH 7.2
CVE-1999-0899

The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an…

Mitigation only
Fix from $1,950 1999-11-04
Commercial Internet System HIGH 7.5
CVE-1999-0777EPSS 12%

IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.

Mitigation only
Fix from $1,950 1999-09-23
Terminal Server HIGH 7.5
CVE-1999-0909EPSS 12%

Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed …

Mitigation only
Fix from $1,950 1999-09-20
Data Access Components HIGH 10.0
CVE-1999-1011EPSS 77%

The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allow…

Mitigation only
Fix from $1,950 1999-07-19
Windows Nt HIGH 7.8
CVE-1999-0728EPSS 6%

A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.

Mitigation only
Fix from $1,950 1999-07-06
Windows Nt HIGH 7.2
CVE-1999-0344

NT users can gain debug-level access on a system process using the Sechole exploit.

Mitigation only
Fix from $1,950 1998-08-01
Windows Nt MEDIUM 5.0
CVE-1999-0227EPSS 5%

Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.

Mitigation only
Fix from $1,600 1997-06-01
Windows Nt HIGH 7.2
CVE-1999-0496

A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.

Mitigation only
Fix from $1,950 1997-01-01