58.518 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.518 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-1999-0989 | HIGH 7.5 | microsoft ie Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol. | 11,9% | — |
| CVE-1999-0909 | HIGH 7.5 | microsoft terminal_server Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability. | 12,0% | — |
| CVE-1999-0889 | HIGH 7.5 | cisco 675_router Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set. | 1,4% | — |
| CVE-1999-0875 | HIGH 7.5 | microsoft windows_2000 DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes. | 10,2% | — |
| CVE-1999-0777 | HIGH 7.5 | microsoft commercial_internet_system IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions. | 12,0% | — |
| CVE-1999-0734 | HIGH 7.5 | cisco ciscosecure A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication. | 1,4% | — |
| CVE-1999-0576 | HIGH 7.5 | microsoft windows_nt A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories. | 4,9% | — |
| CVE-1999-0575 | HIGH 7.5 | microsoft windows_nt A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking. | 5,2% | — |
| CVE-1999-0562 | HIGH 7.5 | microsoft windows_2000 The registry in Windows NT can be accessed remotely by users who are not administrators. | 10,1% | — |
| CVE-1999-0537 | HIGH 7.5 | microsoft internet_explorer A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc. | 6,0% | — |
| CVE-1999-0519 | HIGH 7.5 | microsoft outlook A NETBIOS/SMB share password is the default, null, or missing. | 5,6% | — |
| CVE-1999-0518 | HIGH 7.5 | microsoft windows_95 A NETBIOS/SMB share password is guessable. | 4,8% | — |
| CVE-1999-0504 | HIGH 7.5 | microsoft windows_2000 A Windows NT local user or administrator account has a default, null, blank, or missing password. | 64,3% | — |
| CVE-1999-0499 | HIGH 7.5 | microsoft windows_2000 NETBIOS share information may be published through SNMP registry keys in NT. | 4,8% | — |
| CVE-1999-0490 | HIGH 7.5 | microsoft internet_explorer MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag. | 9,9% | — |
| CVE-1999-0488 | HIGH 7.5 | microsoft internet_explorer Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability. | 11,8% | — |
| CVE-1999-0450 | HIGH 7.5 | microsoft internet_information_server In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). | 19,0% | — |
| CVE-1999-0415 | HIGH 7.5 | cisco cisco_7xx_routers The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration. | 1,4% | — |
| CVE-1999-0412 | HIGH 7.5 | microsoft internet_information_server In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. | 10,2% | — |
| CVE-1999-0391 | HIGH 7.5 | microsoft terminal_server The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. | 4,9% | — |
| CVE-1999-0379 | HIGH 7.5 | microsoft backoffice_resource_kit Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting. | 5,8% | — |
| CVE-1999-0366 | HIGH 7.5 | microsoft windows_nt In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. | 3,7% | — |
| CVE-1999-0354 | HIGH 7.5 | microsoft internet_explorer Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client vie | 5,2% | — |
| CVE-1999-0349 | HIGH 7.5 | microsoft internet_information_server A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. | 17,9% | — |
| CVE-1999-0332 | HIGH 7.5 | microsoft netmeeting Buffer overflow in NetMeeting allows denial of service and remote command execution. | 12,8% | — |