Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Outlook MEDIUM 5.0
CVE-2003-0007

Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outloo…

Mitigation only
Fix from $1,600 2003-02-07
Data Access Components HIGH 10.0
CVE-2002-1918EPSS 16%

Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown …

No fix yet
Fix from $1,950 2002-12-31
Windows Media Player HIGH 7.8
CVE-2002-1844

Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users t…

Mitigation only
Fix from $1,950 2002-12-31
Internet Information Services HIGH 7.5
CVE-2002-1745EPSS 18%

Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions con…

Mitigation only
Fix from $1,950 2002-12-31
Windows Media Player HIGH 7.5
CVE-2002-1847EPSS 34%

Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a lo…

No fix yet
Fix from $1,950 2002-12-31
Sql Server HIGH 7.5
CVE-2002-1872EPSS 6%

Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff a…

Mitigation only
Fix from $1,950 2002-12-31
Outlook HIGH 7.5
CVE-2002-2101EPSS 11%

Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:…

Mitigation only
Fix from $1,950 2002-12-31
Windows 2000 Terminal Services HIGH 7.2
CVE-2002-1933

The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could …

Mitigation only
Fix from $1,950 2002-12-31
Ie MEDIUM 6.4
CVE-2002-2125EPSS 8%

Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate …

Mitigation only
Fix from $1,600 2002-12-31
Internet Explorer MEDIUM 6.4
CVE-2002-2311EPSS 10%

Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to…

No fix yet
Fix from $1,600 2002-12-31
Network Firmware MEDIUM 6.4
CVE-2002-2380EPSS 11%

NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented u…

Mitigation only
Fix from $1,600 2002-12-31
Internet Information Server MEDIUM 5.0
CVE-2002-1694EPSS 13%

Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attac…

Mitigation only
Fix from $1,600 2002-12-31
Internet Information Server MEDIUM 5.0
CVE-2002-1695EPSS 14%

Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the…

Mitigation only
Fix from $1,600 2002-12-31
Msn Messenger MEDIUM 5.0
CVE-2002-1698EPSS 16%

Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) …

Mitigation only
Fix from $1,600 2002-12-31
Ie MEDIUM 5.0
CVE-2002-1714EPSS 19%

Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the D…

Mitigation only
Fix from $1,600 2002-12-31
Office MEDIUM 5.0
CVE-2002-1716EPSS 14%

The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote attackers to create arbitrary files using the SaveAs …

Mitigation only
Fix from $1,600 2002-12-31
Internet Information Services MEDIUM 5.0
CVE-2002-1717EPSS 16%

Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1) /_vti_pvt/access.cnf, (2) /…

Mitigation only
Fix from $1,600 2002-12-31
Internet Information Services MEDIUM 5.0
CVE-2002-1718EPSS 14%

Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a Frontpage Server Extension (FPSE) file, as claim…

Mitigation only
Fix from $1,600 2002-12-31
Internet Information Services MEDIUM 5.0
CVE-2002-1744EPSS 65%

Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arb…

No fix yet
Fix from $1,600 2002-12-31
Baseline Security Analyzer MEDIUM 5.0
CVE-2002-1762EPSS 16%

Microsoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans in plainte…

No fix yet
Fix from $1,600 2002-12-31
Ie MEDIUM 5.0
CVE-2002-1824

Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate chain during a SSL/TLS handshake, does not prompt the …

Mitigation only
Fix from $1,600 2002-12-31
Msn Messenger MEDIUM 5.0
CVE-2002-1831EPSS 22%

Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-…

No fix yet
Fix from $1,600 2002-12-31
Exchange Server MEDIUM 5.0
CVE-2002-1873EPSS 14%

Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memor…

Mitigation only
Fix from $1,600 2002-12-31
Sql Server MEDIUM 5.0
CVE-2002-1981

Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo s…

Mitigation only
Fix from $1,600 2002-12-31
Site Server MEDIUM 5.0
CVE-2002-2081EPSS 14%

cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a lon…

Mitigation only
Fix from $1,600 2002-12-31
Outlook MEDIUM 5.0
CVE-2002-2100EPSS 11%

Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an …

Mitigation only
Fix from $1,600 2002-12-31
Windows 2000 HIGH 10.0
CVE-2002-1257EPSS 15%

Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that i…

Mitigation only
Fix from $1,950 2002-12-23
Windows 2000 HIGH 7.5
CVE-2002-1260EPSS 16%

The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks an…

Mitigation only
Fix from $1,950 2002-12-23
Windows 2000 MEDIUM 5.0
CVE-2002-1256EPSS 5%

The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digita…

Mitigation only
Fix from $1,600 2002-12-23
Windows 2000 MEDIUM 5.0
CVE-2002-1258EPSS 15%

Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow …

Mitigation only
Fix from $1,600 2002-12-23