Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

W3who.dll MEDIUM 6.8
CVE-2004-1133EPSS 10%

Multiple cross-site scripting (XSS) vulnerabilities in Microsoft W3Who ISAPI (w3who.dll) allow remote attackers to inject arbitrary HTML and web scri…

Mitigation only
Fix from $1,600 2005-01-10
Windows Nt MEDIUM 5.0
CVE-2004-0899EPSS 73%

The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the le…

Mitigation only
Fix from $1,600 2005-01-10
Ie HIGH 10.0
CVE-2004-0985EPSS 20%

Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated using a document with a draggable file typ…

Mitigation only
Fix from $1,950 2004-12-31
Windows 2000 HIGH 8.4
CVE-2004-2339

Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or …

Mitigation only
Fix from $1,950 2004-12-31
Ie HIGH 7.5
CVE-2004-1104EPSS 35%

Microsoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page …

No fix yet
Fix from $1,950 2004-12-31
Ie HIGH 7.5
CVE-2004-1155EPSS 13%

Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose …

No fix yet
Fix from $1,950 2004-12-31
Ie HIGH 7.5
CVE-2004-1166EPSS 39%

CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via a…

No fix yet
Fix from $1,950 2004-12-31
Ie HIGH 7.5
CVE-2004-2291EPSS 11%

Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objec…

No fix yet
Fix from $1,950 2004-12-31
Outlook Express MEDIUM 5.8
CVE-2004-2694EPSS 9%

Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook co…

Mitigation only
Fix from $1,600 2004-12-31
Windows 2000 MEDIUM 5.1
CVE-2004-1049EPSS 31%

Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ic…

No fix yet
Fix from $1,600 2004-12-31
Windows 2000 MEDIUM 5.1
CVE-2004-1306EPSS 20%

Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers …

No fix yet
Fix from $1,600 2004-12-31
Ie MEDIUM 5.1
CVE-2004-2383EPSS 20%

Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from oth…

No fix yet
Fix from $1,600 2004-12-31
Sql Server MEDIUM 5.0
CVE-2004-1560EPSS 26%

Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long request to TCP port 1433, possibl…

No fix yet
Fix from $1,600 2004-12-31
Frontpage MEDIUM 5.0
CVE-2004-2179EPSS 12%

asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG imag…

No fix yet
Fix from $1,600 2004-12-31
Ie MEDIUM 5.0
CVE-2004-2434EPSS 33%

Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brac…

No fix yet
Fix from $1,600 2004-12-31
Outlook MEDIUM 5.0
CVE-2004-2482EPSS 13%

Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properl…

Mitigation only
Fix from $1,600 2004-12-31
Windows 2000 MEDIUM 5.0
CVE-2004-1361EPSS 20%

Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execut…

No fix yet
Fix from $1,600 2004-12-23
Mn 500 Wireless Base Station MEDIUM 5.0
CVE-2004-0610EPSS 15%

The Web administration interface in Microsoft MN-500 Wireless Router allows remote attackers to cause a denial of service (connection refusal) via a …

Mitigation only
Fix from $1,600 2004-12-06
Windows 2000 HIGH 10.0
CVE-2004-0209EPSS 57%

Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attacke…

Mitigation only
Fix from $1,950 2004-11-03
Internet Explorer HIGH 10.0
CVE-2004-0214EPSS 47%

Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious se…

Mitigation only
Fix from $1,950 2004-11-03
Windows 2003 Server HIGH 10.0
CVE-2004-0575EPSS 60%

Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition all…

Mitigation only
Fix from $1,950 2004-11-03
Windows Nt HIGH 7.5
CVE-2004-0569EPSS 19%

The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a …

Mitigation only
Fix from $1,950 2004-11-03
Internet Information Server MEDIUM 5.0
CVE-2003-0718EPSS 88%

The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and…

Mitigation only
Fix from $1,600 2004-11-03
.net Framework HIGH 9.3
CVE-2004-0200EPSS 49%

Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attacker…

Mitigation only
Fix from $1,950 2004-09-28
Frontpage HIGH 7.5
CVE-2004-0573EPSS 42%

Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remo…

Mitigation only
Fix from $1,950 2004-09-28
Ie MEDIUM 5.0
CVE-2004-0869EPSS 15%

Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in th…

No fix yet
Fix from $1,600 2004-09-16
Ie MEDIUM 5.0
CVE-2004-1686EPSS 10%

Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt for ActiveX and Javascript via an XHTML page tha…

Mitigation only
Fix from $1,600 2004-09-15
Outlook MEDIUM 5.0
CVE-2004-0501EPSS 19%

Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail …

No fix yet
Fix from $1,600 2004-08-18
Outlook MEDIUM 5.0
CVE-2004-0502EPSS 20%

Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message,…

No fix yet
Fix from $1,600 2004-08-18
Ie MEDIUM 5.0
CVE-2004-0526EPSS 17%

Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "a…

No fix yet
Fix from $1,600 2004-08-06