Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

File Transfer Manager MEDIUM 5.0
CVE-2002-0978EPSS 8%

Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations…

Mitigation only
Fix from $1,600 2002-09-24
Data Engine HIGH 10.0
CVE-2002-0721EPSS 46%

Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which coul…

Mitigation only
Fix from $1,950 2002-09-05
Jet HIGH 7.5
CVE-2002-0859EPSS 26%

Buffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code.

Mitigation only
Fix from $1,950 2002-09-05
Windows 2000 HIGH 7.2
CVE-2002-0720

A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the…

Mitigation only
Fix from $1,950 2002-09-05
Windows 2000 MEDIUM 5.5
CVE-2002-0725

NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, whic…

Mitigation only
Fix from $1,600 2002-09-05
Metadirectory Services HIGH 10.0
CVE-2002-0697EPSS 18%

Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to dire…

Mitigation only
Fix from $1,950 2002-08-12
Excel HIGH 7.5
CVE-2002-0618EPSS 14%

The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding…

Mitigation only
Fix from $1,950 2002-08-12
Office HIGH 7.5
CVE-2002-0619EPSS 16%

The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic…

Mitigation only
Fix from $1,950 2002-08-12
Data Engine HIGH 7.5
CVE-2002-0644EPSS 11%

Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows member…

Mitigation only
Fix from $1,950 2002-08-12
Data Engine HIGH 7.5
CVE-2002-0645

SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users…

Mitigation only
Fix from $1,950 2002-08-12
Data Engine HIGH 7.5
CVE-2002-0649EPSS 85%

Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to …

Mitigation only
Fix from $1,950 2002-08-12
Data Access Components HIGH 7.5
CVE-2002-0695EPSS 17%

Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 200…

Mitigation only
Fix from $1,950 2002-08-12
Content Management Server HIGH 7.5
CVE-2002-0700EPSS 8%

Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execut…

Mitigation only
Fix from $1,950 2002-08-12
Content Management Server HIGH 7.5
CVE-2002-0718EPSS 6%

Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying…

Mitigation only
Fix from $1,950 2002-08-12
Content Management Server HIGH 7.5
CVE-2002-0719EPSS 10%

SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2002-08-12
Internet Explorer HIGH 7.5
CVE-2002-0815

The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to acce…

Mitigation only
Fix from $1,950 2002-08-12
Windows Help HIGH 7.5
CVE-2002-0823EPSS 26%

Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCt…

Mitigation only
Fix from $1,950 2002-08-12
Excel MEDIUM 5.1
CVE-2002-0616EPSS 10%

The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by attaching an inline macro to an obje…

Mitigation only
Fix from $1,600 2002-08-12
Excel MEDIUM 5.1
CVE-2002-0617EPSS 11%

The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing sh…

Mitigation only
Fix from $1,600 2002-08-12
Internet Information Server MEDIUM 5.0
CVE-2002-0419EPSS 38%

Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks …

No fix yet
Fix from $1,600 2002-08-12
Msn Messenger MEDIUM 5.0
CVE-2002-0472EPSS 12%

MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attack…

Mitigation only
Fix from $1,600 2002-08-12
Sql Server MEDIUM 5.0
CVE-2002-0650EPSS 18%

The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" styl…

Mitigation only
Fix from $1,600 2002-08-12
Sql Server MEDIUM 5.0
CVE-2002-0729EPSS 11%

Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.

Mitigation only
Fix from $1,600 2002-08-12
.net Framework HIGH 10.0
CVE-2002-0369EPSS 24%

Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbitrary code via a ro…

Mitigation only
Fix from $1,950 2002-07-26
Windows 2000 Terminal Services HIGH 7.5
CVE-2002-0444EPSS 12%

Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users…

Mitigation only
Fix from $1,950 2002-07-26
.net Framework MEDIUM 5.0
CVE-2002-0409EPSS 19%

orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers t…

Mitigation only
Fix from $1,600 2002-07-26
Msde HIGH 7.5
CVE-2002-0624EPSS 23%

Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows r…

Mitigation only
Fix from $1,950 2002-07-23
Msde HIGH 7.5
CVE-2002-0641EPSS 11%

Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers wi…

Mitigation only
Fix from $1,950 2002-07-23
Msde HIGH 7.2
CVE-2002-0642EPSS 50%

The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (M…

Mitigation only
Fix from $1,950 2002-07-23
Internet Information Server HIGH 7.5
CVE-2002-0364EPSS 31%

Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR re…

Mitigation only
Fix from $1,950 2002-07-03