Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Msn Messenger Service MEDIUM 5.0
CVE-2005-2225EPSS 16%

Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message containing the ".pif" string, which is interpret…

No fix yet
Fix from $1,600 2005-07-12
Windows 2000 MEDIUM 5.0
CVE-2005-2150EPSS 19%

Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes…

Mitigation only
Fix from $1,600 2005-07-11
Ie MEDIUM 5.0
CVE-2005-2087EPSS 61%

Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a…

Mitigation only
Fix from $1,600 2005-07-05
Frontpage MEDIUM 5.0
CVE-2005-2143

Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.

No fix yet
Fix from $1,600 2005-07-05
Windows 2000 HIGH 7.5
CVE-2005-1935EPSS 27%

Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code …

No fix yet
Fix from $1,950 2005-06-13
Remote Desktop Connection HIGH 7.4
CVE-2005-1794EPSS 16%

Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which …

Mitigation only
Fix from $1,950 2005-06-01
Isa Server MEDIUM 5.0
CVE-2005-1907EPSS 19%

The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wsps…

Mitigation only
Fix from $1,600 2005-05-31
Asp.net MEDIUM 6.4
CVE-2005-1664EPSS 19%

The __VIEWSTATE functionality in Microsoft ASP.NET 1.x allows remote attackers to conduct replay attacks to (1) apply a ViewState generated from one …

Mitigation only
Fix from $1,600 2005-05-18
Windows 2003 Server MEDIUM 5.0
CVE-2005-1649EPSS 22%

The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attackers to cause a denial of ser…

No fix yet
Fix from $1,600 2005-05-18
Asp.net MEDIUM 5.0
CVE-2005-1665EPSS 40%

The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU …

Mitigation only
Fix from $1,600 2005-05-18
Windows Media Player HIGH 7.5
CVE-2005-1574EPSS 5%

Windows Media Player 9 and 10, in certain cases, allows content protected by Windows Media Digital Rights Management (WMDRM) to redirect the user to …

Mitigation only
Fix from $1,950 2005-05-14
Windows 2000 HIGH 10.0
CVE-2005-0059EPSS 73%

Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a…

Mitigation only
Fix from $1,950 2005-05-02
Windows 2000 HIGH 7.2
CVE-2005-0060

Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gai…

Mitigation only
Fix from $1,950 2005-05-02
Windows 2000 HIGH 7.2
CVE-2005-0061

The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access reques…

Mitigation only
Fix from $1,950 2005-05-02
Word MEDIUM 5.1
CVE-2005-0558EPSS 15%

Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.

Mitigation only
Fix from $1,600 2005-05-02
Ie MEDIUM 5.0
CVE-2005-0500EPSS 11%

Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in a titlebar for a script-initiated popup window, …

No fix yet
Fix from $1,600 2005-05-02
Internet Explorer MEDIUM 5.0
CVE-2005-0954EPSS 15%

Windows Explorer and Internet Explorer in Windows 2000 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a malformed Win…

Mitigation only
Fix from $1,600 2005-05-02
Outlook MEDIUM 5.0
CVE-2005-1052EPSS 9%

Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, wh…

Mitigation only
Fix from $1,600 2005-05-02
Windows 2000 MEDIUM 5.0
CVE-2005-1184EPSS 33%

The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the corre…

Mitigation only
Fix from $1,600 2005-05-02
Exchange Server MEDIUM 5.8
CVE-2005-0420EPSS 26%

Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the …

No fix yet
Fix from $1,600 2005-04-27
Windows 2000 MEDIUM 5.0
CVE-2004-0790EPSS 80%

Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages,…

Mitigation only
Fix from $1,600 2005-04-12
Windows 2003 Server MEDIUM 5.0
CVE-2005-0688EPSS 47%

Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP pa…

Mitigation only
Fix from $1,600 2005-03-05
Word HIGH 10.0
CVE-2004-0963EPSS 33%

Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (applica…

Mitigation only
Fix from $1,950 2005-02-09
Windows 2000 HIGH 10.0
CVE-2004-0568EPSS 35%

HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that…

Mitigation only
Fix from $1,950 2005-01-10
Windows 2000 HIGH 10.0
CVE-2004-0571EPSS 31%

Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via…

Mitigation only
Fix from $1,950 2005-01-10
Windows Nt HIGH 10.0
CVE-2004-0900EPSS 26%

The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, wh…

Mitigation only
Fix from $1,950 2005-01-10
Windows 2000 HIGH 10.0
CVE-2004-0901EPSS 32%

Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote att…

Mitigation only
Fix from $1,950 2005-01-10
W3who.dll HIGH 10.0
CVE-2004-1134EPSS 72%

Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via…

Mitigation only
Fix from $1,950 2005-01-10
Windows 2000 HIGH 7.2
CVE-2004-0893

The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properl…

Mitigation only
Fix from $1,950 2005-01-10
Windows 2000 HIGH 7.2
CVE-2004-0894

LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, …

Mitigation only
Fix from $1,950 2005-01-10