Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2003-0007 Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outloo… Outlook Mitigation only Fix from $1,6002003-02-07 HIGH 10.0 CVE-2002-1918EPSS 16% Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown … Data Access Components No fix yet Fix from $1,9502002-12-31 HIGH 7.8 CVE-2002-1844 Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users t… Windows Media Player Mitigation only Fix from $1,9502002-12-31 HIGH 7.5 CVE-2002-1745EPSS 18% Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions con… Internet Information Services Mitigation only Fix from $1,9502002-12-31 HIGH 7.5 CVE-2002-1847EPSS 34% Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a lo… Windows Media Player No fix yet Fix from $1,9502002-12-31 HIGH 7.5 CVE-2002-1872EPSS 6% Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff a… Sql Server Mitigation only Fix from $1,9502002-12-31 HIGH 7.5 CVE-2002-2101EPSS 11% Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:… Outlook Mitigation only Fix from $1,9502002-12-31 HIGH 7.2 CVE-2002-1933 The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could … Windows 2000 Terminal Services Mitigation only Fix from $1,9502002-12-31 MEDIUM 6.4 CVE-2002-2125EPSS 8% Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate … Ie Mitigation only Fix from $1,6002002-12-31 MEDIUM 6.4 CVE-2002-2311EPSS 10% Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to… Internet Explorer No fix yet Fix from $1,6002002-12-31 MEDIUM 6.4 CVE-2002-2380EPSS 11% NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented u… Network Firmware Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1694EPSS 13% Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attac… Internet Information Server Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1695EPSS 14% Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the… Internet Information Server Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1698EPSS 16% Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) … Msn Messenger Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1714EPSS 19% Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the D… Ie Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1716EPSS 14% The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote attackers to create arbitrary files using the SaveAs … Office Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1717EPSS 16% Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1) /_vti_pvt/access.cnf, (2) /… Internet Information Services Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1718EPSS 14% Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a Frontpage Server Extension (FPSE) file, as claim… Internet Information Services Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1744EPSS 65% Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arb… Internet Information Services No fix yet Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1762EPSS 16% Microsoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans in plainte… Baseline Security Analyzer No fix yet Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1824 Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate chain during a SSL/TLS handshake, does not prompt the … Ie Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1831EPSS 22% Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-… Msn Messenger No fix yet Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1873EPSS 14% Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memor… Exchange Server Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-1981 Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo s… Sql Server Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-2081EPSS 14% cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a lon… Site Server Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-2100EPSS 11% Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an … Outlook Mitigation only Fix from $1,6002002-12-31 HIGH 10.0 CVE-2002-1257EPSS 15% Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that i… Windows 2000 Mitigation only Fix from $1,9502002-12-23 HIGH 7.5 CVE-2002-1260EPSS 16% The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks an… Windows 2000 Mitigation only Fix from $1,9502002-12-23 MEDIUM 5.0 CVE-2002-1256EPSS 5% The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digita… Windows 2000 Mitigation only Fix from $1,6002002-12-23 MEDIUM 5.0 CVE-2002-1258EPSS 15% Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow … Windows 2000 Mitigation only Fix from $1,6002002-12-23