56.707 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.707 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2002-1558 | HIGH 10.0 | cisco optical_networking_systems_software Cisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed or disabled, which allows remote attackers to gain privileges by connecting to the account via Telnet. | 2.8% | — |
| CVE-2002-1360 | HIGH 10.0 | cisco ios Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to inter | 6.1% | — |
| CVE-2002-1359 | HIGH 10.0 | cisco ios Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol | 80.2% | — |
| CVE-2002-1358 | HIGH 10.0 | cisco ios Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite. | 5.8% | — |
| CVE-2002-1357 | HIGH 10.0 | cisco ios Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol | 9.8% | — |
| CVE-2002-1257 | HIGH 10.0 | microsoft windows_2000 Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail. | 15.3% | — |
| CVE-2002-1145 | HIGH 10.0 | microsoft data_engine The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a | 8.3% | — |
| CVE-2002-0736 | HIGH 10.0 | microsoft backoffice Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank. | 31.6% | — |
| CVE-2002-0721 | HIGH 10.0 | microsoft data_engine Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileg | 46.3% | — |
| CVE-2002-0697 | HIGH 10.0 | microsoft metadirectory_services Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials. | 18.0% | — |
| CVE-2002-0369 | HIGH 10.0 | microsoft .net_framework Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbitrary code via a routine that processes cookies while in StateServer mode. | 24.3% | — |
| CVE-2002-0018 | HIGH 10.0 | microsoft windows_2000 In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator p | 16.4% | — |
| CVE-2001-0538 | HIGH 10.0 | microsoft outlook Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page. | 52.9% | — |
| CVE-2001-0500 | HIGH 10.0 | microsoft index_server Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.id | 96.7% | — |
| CVE-2001-0241 | HIGH 10.0 | microsoft windows_2000 Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0. | 85.7% | — |
| CVE-2001-0147 | HIGH 10.0 | microsoft windows_2000 Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records. | 6.2% | — |
| CVE-2001-0045 | HIGH 10.0 | microsoft windows_nt The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities. | 8.4% | — |
| CVE-2000-1209 | HIGH 10.0 | compaq insight_manager The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight | 87.3% | — |
| CVE-2000-1089 | HIGH 10.0 | microsoft windows_2000 Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability. | 74.6% | — |
| CVE-2000-1055 | HIGH 10.0 | cisco secure_access_control_server Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet. | 4.0% | — |
| CVE-2000-1054 | HIGH 10.0 | cisco secure_access_control_server Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large packet. | 8.4% | — |
| CVE-2000-1034 | HIGH 10.0 | microsoft windows_2000 Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability. | 27.2% | — |
| CVE-2000-0945 | HIGH 10.0 | cisco catalyst_3500_xl The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory. | 72.6% | — |
| CVE-2000-0854 | HIGH 10.0 | microsoft office When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same director | 37.2% | — |
| CVE-2000-0788 | HIGH 10.0 | microsoft access The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands. | 8.4% | — |