58.460 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.460 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2004-0493 | MED 6.4 | apache http_server The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines wit | 84,8% | — |
| CVE-2003-0348 | MED 6.4 | microsoft windows_media_player A certain Microsoft Windows Media Player 9 Series ActiveX control allows remote attackers to view and manipulate the Media Library on the local system via HTML script. | 19,9% | — |
| CVE-2003-0192 | MED 6.4 | apache http_server Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause | 6,0% | — |
| CVE-2002-2380 | MED 6.4 | microsoft network_firmware NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented usernames and passwords from network traffic. | 10,9% | — |
| CVE-2002-2311 | MED 6.4 | microsoft internet_explorer Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was r | 9,5% | — |
| CVE-2002-2139 | MED 6.4 | cisco pix_firewall_software Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack. | 1,2% | — |
| CVE-2002-2125 | MED 6.4 | microsoft ie Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate is in the user's local repository, which could allow remote attackers to decrypt web sessions via a man-in-the- | 8,3% | — |
| CVE-2002-1290 | MED 6.4 | microsoft java_virtual_machine The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class. | 14,3% | — |
| CVE-2002-1188 | MED 6.4 | microsoft internet_explorer Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "T | 12,3% | — |
| CVE-2002-0976 | MED 6.4 | microsoft internet_explorer Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet. | 14,3% | — |
| CVE-2002-0882 | MED 6.4 | cisco skinny_client_control_protocol_software The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) the po | 2,7% | — |
| CVE-2002-0769 | MED 6.4 | cisco ata-186 The web-based configuration interface for the Cisco ATA 186 Analog Telephone Adaptor allows remote attackers to bypass authentication via an HTTP POST request with a single byte, which allows the attackers to (1) obtain the password from the login screen, or ( | 8,5% | — |
| CVE-2002-0049 | MED 6.4 | microsoft exchange_server Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys. | 13,3% | — |
| CVE-2001-1210 | MED 6.4 | cisco ubr920 Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community s | 2,3% | — |
| CVE-2001-0723 | MED 6.4 | microsoft internet_explorer Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability." | 11,4% | — |
| CVE-2001-0722 | MED 6.4 | microsoft internet_explorer Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability." | 27,6% | — |
| CVE-2000-0979 | MED 6.4 | microsoft windows_95 File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the r | 45,0% | — |
| CVE-2000-0770 | MED 6.4 | microsoft internet_information_server IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" | 15,1% | — |
| CVE-2000-0760 | MED 6.4 | apache tomcat The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension. | 62,5% | — |
| CVE-2000-0759 | MED 6.4 | apache tomcat Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path. | 25,7% | — |
| CVE-2000-0024 | MED 6.4 | microsoft internet_information_server IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability. | 12,2% | — |
| CVE-1999-1361 | MED 6.4 | microsoft windows_nt Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages. | 8,6% | — |
| CVE-1999-1097 | MED 6.4 | microsoft netmeeting Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty. | 3,8% | — |
| CVE-1999-0191 | MED 6.4 | microsoft internet_information_server IIS newdsn.exe CGI script allows remote users to overwrite files. | 53,3% | — |
| CVE-1999-0183 | MED 6.4 | linux linux_kernel Linux implementations of TFTP would allow access to files outside the restricted directory. | 1,6% | — |