CSV
172,057 results for "vulnerability" Page 7
CVE-2000-0457 Exploit

ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.

May 11, 2000 2 affected product(s) NVD
7.5
CVSS
84.4%
EPSS
⚡ 65.3
CVE-2000-0246 Exploit

IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.

Mar 30, 2000 7 affected product(s) NVD
5.0
CVSS
83.6%
EPSS
⚡ 55.1
CVE-2000-0408 Exploit

IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.

May 11, 2000 2 affected product(s) NVD
5.0
CVSS
74.0%
EPSS
⚡ 52.2
CVE-2000-0305

Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.

May 19, 2000 6 affected product(s) NVD
7.8
CVSS
41.0%
EPSS
⚡ 43.5
CVE-2000-0402 Exploit

The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.

May 30, 2000 3 affected product(s) NVD
2.1
CVSS
78.5%
EPSS
⚡ 41.9
CVE-2000-0245

Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts.

Mar 27, 2000 8 affected product(s) NVD
10.0
CVSS
5.9%
EPSS
⚡ 41.8
CVE-2000-0097

The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability.

Jan 26, 2000 1 affected product(s) NVD
5.0
CVSS
60.9%
EPSS
⚡ 38.3
CVE-2000-0256

Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability.

Apr 19, 2000 3 affected product(s) NVD
7.5
CVSS
21.6%
EPSS
⚡ 36.5
CVE-2000-0258 HIGH

IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.

Apr 12, 2000 2 affected product(s) NVD
7.5
CVSS
20.3%
EPSS
⚡ 36.1
CVE-2000-0304

Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.

May 10, 2000 2 affected product(s) NVD
5.0
CVSS
51.7%
EPSS
⚡ 35.5
CVE-2000-0464

Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability.

May 17, 2000 4 affected product(s) NVD
7.6
CVSS
15.1%
EPSS
⚡ 34.9
CVE-2000-0260

Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link View Server-Side Component" vulnerability.

Apr 14, 2000 2 affected product(s) NVD
7.5
CVSS
15.0%
EPSS
⚡ 34.5
CVE-2000-0419

The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.

May 11, 2000 10 affected product(s) NVD
7.5
CVSS
14.2%
EPSS
⚡ 34.3
CVE-2000-0450

Vulnerability in bbd server in Big Brother System and Network Monitor allows an attacker to execute arbitrary commands.

May 18, 2000 4 affected product(s) NVD
7.5
CVSS
0.9%
EPSS
⚡ 30.3
CVE-2000-0277

Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.

Apr 3, 2000 2 affected product(s) NVD
7.2
CVSS
1.7%
EPSS
⚡ 29.3
CVE-2000-0215

Vulnerability in SCO cu program in UnixWare 7.x allows local users to gain privileges.

Feb 8, 2000 4 affected product(s) NVD
7.2
CVSS
0.1%
EPSS
⚡ 28.8
CVE-2000-0247

Unknown vulnerability in Generic-NQS (GNQS) allows local users to gain root privileges.

Mar 22, 2000 2 affected product(s) NVD
7.2
CVSS
0.0%
EPSS
⚡ 28.8
CVE-2000-0211

The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerability.

Feb 23, 2000 2 affected product(s) NVD
5.0
CVSS
26.6%
EPSS
⚡ 28
CVE-2000-0465

Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability.

May 17, 2000 4 affected product(s) NVD
5.1
CVSS
24.5%
EPSS
⚡ 27.8
CVE-2000-0404

The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability.

May 25, 2000 5 affected product(s) NVD
5.0
CVSS
24.3%
EPSS
⚡ 27.3