Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Office MEDIUM 5.0
CVE-2006-0004EPSS 32%

Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information v…

Mitigation only
Fix from $1,600 2006-02-14
Windows Nt HIGH 9.3
CVE-2006-0005EPSS 39%

Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the d…

Mitigation only
Fix from $1,950 2006-02-14
Html Help HIGH 7.5
CVE-2006-0564EPSS 72%

Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.…

Mitigation only
Fix from $1,950 2006-02-06
Ie HIGH 7.5
CVE-2006-0544EPSS 22%

urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and po…

No fix yet
Fix from $1,950 2006-02-04
Windows 2000 HIGH 7.5
CVE-2006-0376EPSS 18%

The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) i…

Mitigation only
Fix from $1,950 2006-01-22
Visual Studio .net MEDIUM 5.1
CVE-2006-0187EPSS 19%

By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which a…

No fix yet
Fix from $1,600 2006-01-12
Ie HIGH 7.5
CVE-2005-4827EPSS 11%

Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of th…

No fix yet
Fix from $1,950 2005-12-31
Ie MEDIUM 5.1
CVE-2005-3240EPSS 6%

Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a use…

Mitigation only
Fix from $1,600 2005-12-31
Ie MEDIUM 5.0
CVE-2005-4679EPSS 8%

Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to spoof the URL in the status bar via the title in an image in a link to a…

Mitigation only
Fix from $1,600 2005-12-31
Ie MEDIUM 5.0
CVE-2005-4717EPSS 16%

Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote a…

No fix yet
Fix from $1,600 2005-12-31
Windows 2003 Server HIGH 7.5
CVE-2005-4560EPSS 86%

The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metaf…

No fix yet
Fix from $1,950 2005-12-28
Ie HIGH 7.8
CVE-2005-4269

mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by ca…

Mitigation only
Fix from $1,950 2005-12-15
Ie HIGH 7.1
CVE-2005-4089EPSS 22%

Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @impor…

No fix yet
Fix from $1,950 2005-12-08
Windows 2000 HIGH 7.8
CVE-2005-3945EPSS 12%

The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data,…

Mitigation only
Fix from $1,950 2005-12-01
Antispyware HIGH 7.2
CVE-2005-2940

Unquoted Windows search path vulnerability in Microsoft Antispyware 1.0.509 (Beta 1) might allow local users to gain privileges via a malicious "prog…

Mitigation only
Fix from $1,950 2005-11-18
Windows 2000 HIGH 10.0
CVE-2005-2122EPSS 44%

Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.…

Mitigation only
Fix from $1,950 2005-10-21
Windows Explorer MEDIUM 5.1
CVE-2005-2117EPSS 37%

Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in previ…

Mitigation only
Fix from $1,600 2005-10-21
Windows 2000 MEDIUM 5.1
CVE-2005-2118EPSS 47%

Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via…

Mitigation only
Fix from $1,600 2005-10-21
Windows 2000 HIGH 7.5
CVE-2005-1985EPSS 37%

The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to exec…

Mitigation only
Fix from $1,950 2005-10-13
Windows 2000 HIGH 7.5
CVE-2005-1978EPSS 53%

COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2005-10-12
Windows 2000 MEDIUM 5.0
CVE-2005-1979EPSS 33%

Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an …

Mitigation only
Fix from $1,600 2005-10-12
Windows 2000 MEDIUM 5.0
CVE-2005-1980EPSS 33%

Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transac…

Mitigation only
Fix from $1,600 2005-10-12
Windows 2000 MEDIUM 5.0
CVE-2005-2119EPSS 36%

The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regar…

Mitigation only
Fix from $1,600 2005-10-12
Windows Media Player MEDIUM 5.0
CVE-2005-2128EPSS 40%

QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn e…

Mitigation only
Fix from $1,600 2005-10-12
Ie For Macintosh MEDIUM 5.0
CVE-2005-3077EPSS 14%

Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page with malformed attributes in…

No fix yet
Fix from $1,600 2005-09-27
Internet Information Server MEDIUM 5.0
CVE-2005-2678EPSS 42%

Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET req…

Mitigation only
Fix from $1,600 2005-08-23
Windows 2000 HIGH 7.2
CVE-2005-2388

Buffer overflow in a certain USB driver, as used on Microsoft Windows, allows attackers to execute arbitrary code.

No fix yet
Fix from $1,950 2005-07-27
Ie HIGH 7.5
CVE-2005-2308EPSS 17%

The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute …

No fix yet
Fix from $1,950 2005-07-19
Internet Explorer MEDIUM 5.0
CVE-2005-2304EPSS 9%

Microsoft MSN Messenger 9.0 and Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) via an image with an ICC Profile w…

No fix yet
Fix from $1,600 2005-07-19
Asp.net MEDIUM 5.0
CVE-2005-2224EPSS 18%

aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a craft…

No fix yet
Fix from $1,600 2005-07-12