Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Internet Information Server MEDIUM 5.0
CVE-2000-0114EPSS 48%

Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_…

Mitigation only
Fix from $1,600 2000-02-02
Outlook Express MEDIUM 5.0
CVE-2000-0105EPSS 21%

Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that ref…

Mitigation only
Fix from $1,600 2000-02-01
Index Server MEDIUM 5.0
CVE-2000-0097EPSS 36%

The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vul…

Mitigation only
Fix from $1,600 2000-01-26
Index Server MEDIUM 5.0
CVE-2000-0098EPSS 49%

Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does …

Mitigation only
Fix from $1,600 2000-01-26
Internet Information Server MEDIUM 5.0
CVE-2000-0126EPSS 46%

Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.

Mitigation only
Fix from $1,600 2000-01-26
Internet Information Server MEDIUM 5.0
CVE-2000-0115EPSS 10%

IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page.

Mitigation only
Fix from $1,600 2000-01-21
Office HIGH 7.2
CVE-2000-0088

Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malfor…

Mitigation only
Fix from $1,950 2000-01-20
Internet Information Server MEDIUM 5.0
CVE-2000-0071EPSS 28%

IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.

Mitigation only
Fix from $1,600 2000-01-11
Hotmail HIGH 10.0
CVE-2000-0081EPSS 19%

Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes…

Mitigation only
Fix from $1,950 2000-01-10
Ie HIGH 10.0
CVE-1999-0876EPSS 6%

Buffer overflow in Internet Explorer 4.0 via EMBED tag.

No fix yet
Fix from $1,950 2000-01-04
Commercial Internet System HIGH 7.5
CVE-2000-0053EPSS 15%

Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.

Mitigation only
Fix from $1,950 2000-01-04
Hotmail HIGH 7.5
CVE-2000-0085EPSS 15%

Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parame…

Mitigation only
Fix from $1,950 2000-01-04
Webtv MEDIUM 5.0
CVE-2000-0082EPSS 15%

WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML.

Mitigation only
Fix from $1,600 2000-01-02
Excel HIGH 7.5
CVE-1999-1055EPSS 7%

Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using th…

Mitigation only
Fix from $1,950 1999-12-31
Powerpoint HIGH 7.5
CVE-1999-1474EPSS 9%

PowerPoint 95 and 97 allows remote attackers to cause an application to be run automatically without prompting the user, possibly through the slide s…

Mitigation only
Fix from $1,950 1999-12-31
Internet Information Server HIGH 7.5
CVE-1999-1591EPSS 11%

Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials …

Mitigation only
Fix from $1,950 1999-12-31
Internet Information Server MEDIUM 5.0
CVE-1999-0154EPSS 40%

IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.

Mitigation only
Fix from $1,600 1999-12-31
Systems Management Server HIGH 7.2
CVE-2000-0100

The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the prog…

Mitigation only
Fix from $1,950 1999-12-29
Ie MEDIUM 5.0
CVE-2000-0036

Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.

Mitigation only
Fix from $1,600 1999-12-22
Internet Information Server MEDIUM 6.4
CVE-2000-0024EPSS 12%

IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape chara…

Mitigation only
Fix from $1,600 1999-12-21
Internet Information Server MEDIUM 5.0
CVE-2000-0025EPSS 35%

IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extens…

Mitigation only
Fix from $1,600 1999-12-21
Windows Nt HIGH 7.8
CVE-1999-0995EPSS 22%

Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function …

Mitigation only
Fix from $1,950 1999-12-16
Windows Nt MEDIUM 5.0
CVE-1999-0994EPSS 7%

Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.

Mitigation only
Fix from $1,600 1999-12-16
Exchange Server HIGH 7.5
CVE-1999-0993EPSS 7%

Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.

Mitigation only
Fix from $1,950 1999-12-13
Ie HIGH 7.5
CVE-1999-0989EPSS 12%

Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.

Mitigation only
Fix from $1,950 1999-12-06
Windows 2000 MEDIUM 5.0
CVE-1999-0819EPSS 15%

NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.

Mitigation only
Fix from $1,600 1999-12-01
Windows 95 HIGH 7.8
CVE-1999-0387EPSS 8%

A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.

Mitigation only
Fix from $1,950 1999-11-29
Ie HIGH 7.2
CVE-1999-0839

Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.

Mitigation only
Fix from $1,950 1999-11-29
Windows Nt HIGH 10.0
CVE-1999-0987

Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.

No fix yet
Fix from $1,950 1999-11-18
Windows 2000 MEDIUM 5.0
CVE-2000-0073EPSS 21%

Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.

No fix yet
Fix from $1,600 1999-11-17