Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Outlook HIGH 7.5
CVE-2001-1088EPSS 20%

Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enable…

No fix yet
Fix from $1,950 2001-06-05
Internet Information Services MEDIUM 5.0
CVE-2001-0151EPSS 68%

IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.

Mitigation only
Fix from $1,600 2001-06-02
Internet Explorer MEDIUM 5.0
CVE-2001-0322EPSS 21%

MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a s…

No fix yet
Fix from $1,600 2001-06-02
Windows Nt HIGH 7.2
CVE-2001-0281

Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may…

No fix yet
Fix from $1,950 2001-05-03
Frontpage MEDIUM 5.0
CVE-1999-0681EPSS 20%

Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause…

No fix yet
Fix from $1,600 2001-03-12
Windows Nt HIGH 7.5
CVE-2001-0047EPSS 6%

The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft…

Mitigation only
Fix from $1,950 2001-02-16
Powerpoint MEDIUM 6.2
CVE-2001-0005

Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.

Mitigation only
Fix from $1,600 2001-02-12
Internet Information Server MEDIUM 5.0
CVE-2000-1090EPSS 17%

Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-b…

Mitigation only
Fix from $1,600 2001-02-12
Internet Information Server MEDIUM 5.0
CVE-2001-0004EPSS 28%

IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, whic…

Mitigation only
Fix from $1,600 2001-02-12
Windows Media Services MEDIUM 5.0
CVE-2001-0083EPSS 17%

Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak th…

Mitigation only
Fix from $1,600 2001-02-12
Internet Information Server MEDIUM 5.0
CVE-2001-0096EPSS 20%

FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed W…

Mitigation only
Fix from $1,600 2001-02-12
Internet Information Server HIGH 7.5
CVE-2000-1104EPSS 6%

Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator t…

Mitigation only
Fix from $1,950 2001-01-09
Windows Embedded Compact HIGH 7.5
CVE-2001-0162EPSS 15%

WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.

No fix yet
Fix from $1,950 2001-01-01
Windows 2000 MEDIUM 5.0
CVE-2000-1227EPSS 13%

Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegpro…

Mitigation only
Fix from $1,600 2000-12-31
Network Monitor HIGH 7.5
CVE-2000-0817EPSS 15%

Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malforme…

Mitigation only
Fix from $1,950 2000-12-19
Internet Information Server HIGH 7.5
CVE-2000-0884EPSS 72%

IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that c…

Mitigation only
Fix from $1,950 2000-12-19
Systems Management Server HIGH 7.5
CVE-2000-0885EPSS 13%

Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse …

Mitigation only
Fix from $1,950 2000-12-19
Internet Information Server HIGH 7.5
CVE-2000-0886EPSS 69%

IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating sy…

Mitigation only
Fix from $1,950 2000-12-19
Internet Information Server HIGH 7.5
CVE-2000-0970EPSS 46%

IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the sec…

Mitigation only
Fix from $1,950 2000-12-19
Windows Nt MEDIUM 5.0
CVE-1999-1579EPSS 22%

The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers…

Mitigation only
Fix from $1,600 2000-12-14
Ie MEDIUM 5.1
CVE-2000-1061EPSS 10%

Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX controls, which allows a remote a…

Mitigation only
Fix from $1,600 2000-12-11
Access HIGH 10.0
CVE-2000-0788EPSS 8%

The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow a…

No fix yet
Fix from $1,950 2000-10-20
Money HIGH 7.2
CVE-2000-0777

The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to …

Mitigation only
Fix from $1,950 2000-10-20
Outlook MEDIUM 5.0
CVE-2000-0756EPSS 5%

Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.

Mitigation only
Fix from $1,600 2000-10-20
Internet Information Services MEDIUM 5.0
CVE-2000-0778EPSS 87%

IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the …

Mitigation only
Fix from $1,600 2000-10-20
Outlook MEDIUM 5.0
CVE-2000-0567EPSS 32%

Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email head…

Mitigation only
Fix from $1,600 2000-07-18
Internet Information Server MEDIUM 5.0
CVE-2000-0630EPSS 68%

IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading v…

Mitigation only
Fix from $1,600 2000-07-17
Windows 95 MEDIUM 5.0
CVE-2000-0612EPSS 9%

Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table.

Mitigation only
Fix from $1,600 2000-06-29
Excel HIGH 7.5
CVE-2000-0597EPSS 12%

Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Expl…

Mitigation only
Fix from $1,950 2000-06-27
Windows Nt MEDIUM 5.0
CVE-2000-0377EPSS 19%

The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the …

Mitigation only
Fix from $1,600 2000-06-08