Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Windows 2000 MEDIUM 5.0
CVE-2003-0661EPSS 25%

The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which…

Mitigation only
Fix from $1,600 2003-10-20
Asp.net MEDIUM 6.8
CVE-2003-0768EPSS 13%

Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character i…

Mitigation only
Fix from $1,600 2003-09-22
Windows 2000 HIGH 10.0
CVE-2003-0715EPSS 40%

Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2003-09-17
Data Access Components HIGH 7.5
CVE-2003-0353EPSS 22%

Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary co…

Mitigation only
Fix from $1,950 2003-08-27
Ie HIGH 7.5
CVE-2003-0530EPSS 30%

Buffer overflow in the BR549.DLL ActiveX control for Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to execute arbitrary code.

Mitigation only
Fix from $1,950 2003-08-27
Ie HIGH 7.5
CVE-2003-0531EPSS 26%

Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in the My Computer domain using the browser cache via…

Mitigation only
Fix from $1,950 2003-08-27
Ie HIGH 7.5
CVE-2003-0532EPSS 23%

Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attack…

No fix yet
Fix from $1,950 2003-08-27
Windows Media Player HIGH 7.5
CVE-2003-0604EPSS 13%

Windows Media Player (WMP) 7 and 8, as running on Internet Explorer and possibly other Microsoft products that process HTML, allows remote attackers …

Mitigation only
Fix from $1,950 2003-08-27
Ie HIGH 7.5
CVE-2003-0701EPSS 30%

Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execu…

Mitigation only
Fix from $1,950 2003-08-27
Data Engine HIGH 7.2
CVE-2003-0230

Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka…

Mitigation only
Fix from $1,950 2003-08-27
Data Engine MEDIUM 5.0
CVE-2003-0231EPSS 36%

Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to …

Mitigation only
Fix from $1,600 2003-08-27
Windows Nt MEDIUM 5.0
CVE-2003-0525EPSS 8%

The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a den…

Mitigation only
Fix from $1,600 2003-08-27
Isa Server MEDIUM 6.8
CVE-2003-0526EPSS 22%

Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrar…

Mitigation only
Fix from $1,600 2003-08-18
Windows 2000 HIGH 7.5
CVE-2003-0469EPSS 45%

Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) …

Mitigation only
Fix from $1,950 2003-08-07
Netmeeting MEDIUM 5.0
CVE-2003-0506EPSS 11%

Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed pack…

Mitigation only
Fix from $1,600 2003-08-07
Windows Media Player MEDIUM 6.4
CVE-2003-0348EPSS 20%

A certain Microsoft Windows Media Player 9 Series ActiveX control allows remote attackers to view and manipulate the Media Library on the local syste…

Mitigation only
Fix from $1,600 2003-07-24
Outlook Express MEDIUM 5.0
CVE-2003-0300

The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values t…

Mitigation only
Fix from $1,600 2003-06-16
Outlook Express MEDIUM 5.0
CVE-2003-0301EPSS 6%

The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large litera…

Mitigation only
Fix from $1,600 2003-06-16
Internet Information Services HIGH 10.0
CVE-2003-0224EPSS 18%

Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a…

Mitigation only
Fix from $1,950 2003-06-09
Internet Information Server MEDIUM 6.8
CVE-2003-0223EPSS 17%

Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and…

Mitigation only
Fix from $1,600 2003-06-09
Internet Information Server MEDIUM 5.0
CVE-2003-0225EPSS 38%

The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing heade…

Mitigation only
Fix from $1,600 2003-06-09
Windows 2000 MEDIUM 5.0
CVE-2003-0227EPSS 34%

The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.…

Mitigation only
Fix from $1,600 2003-06-09
Ie HIGH 7.5
CVE-2003-0113EPSS 39%

Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response…

Mitigation only
Fix from $1,950 2003-05-12
Ie HIGH 7.5
CVE-2003-0115EPSS 12%

Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remo…

Mitigation only
Fix from $1,950 2003-05-12
Biztalk Server HIGH 7.5
CVE-2003-0117EPSS 9%

Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2003-05-12
Biztalk Server HIGH 7.5
CVE-2003-0118EPSS 8%

SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attacke…

Mitigation only
Fix from $1,950 2003-05-12
Ie HIGH 7.5
CVE-2003-0233EPSS 19%

Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() met…

Mitigation only
Fix from $1,950 2003-05-12
Ie MEDIUM 5.0
CVE-2003-0114EPSS 15%

The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system…

Mitigation only
Fix from $1,600 2003-05-12
Ie HIGH 7.5
CVE-2003-1326EPSS 16%

Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary progra…

Mitigation only
Fix from $1,950 2003-02-19
Ie HIGH 7.5
CVE-2003-1328EPSS 39%

The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers t…

Mitigation only
Fix from $1,950 2003-02-19