Vulnerability index

Browse CVEs

73 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
.net Framework HIGH 7.5
CVE-2013-1337EPSS 21%

Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication i…

Mitigation only
Fix from $1,950 2013-05-15
Windows 2003 Server HIGH 7.2
CVE-2011-0039

The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authenticati…

Mitigation only
Fix from $1,950 2011-02-09
Internet Explorer MEDIUM 6.8
CVE-2009-2064

Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which a…

Fix: after 8
Fix from $1,600 2009-06-15
Ie MEDIUM 5.8
CVE-2009-2069

Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which a…

Mitigation only
Fix from $1,600 2009-06-15
Ie MEDIUM 5.8
CVE-2009-2057

Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT respon…

No fix yet
Fix from $1,600 2009-06-15
Internet Information Services HIGH 7.5
CVE-2009-1122EPSS 98%

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote atta…

Patch available
Fix from $1,950 2009-06-10
Internet Information Services HIGH 7.5
CVE-2009-1535EPSS 98%

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, …

Patch available
Fix from $1,950 2009-06-10
Office Sharepoint Server HIGH 7.5
CVE-2008-4032EPSS 48%

Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for ad…

Mitigation only
Fix from $1,950 2008-12-10
Windows HIGH 9.3
CVE-2008-4037EPSS 59%

Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers …

Patch available
Fix from $1,950 2008-11-12
Host Integration Server 2000 HIGH 10.0
CVE-2008-3466EPSS 78%

Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to …

Patch available
Fix from $1,950 2008-10-15
Windows Nt HIGH 10.0
CVE-1999-0987

Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.

No fix yet
Fix from $1,950 1999-11-18
Terminal Server MEDIUM 5.0
CVE-1999-0680EPSS 6%

Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.

Patch available
Fix from $1,600 1999-08-09
Windows Nt HIGH 7.5
CVE-1999-0366

In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash val…

Mitigation only
Fix from $1,950 1999-02-08