CSV
172,059 results for "vulnerability" Page 8
CVE-2000-0457 Exploit

ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.

May 11, 2000 2 affected product(s) NVD
7.5
CVSS
84.4%
EPSS
⚡ 65.3
CVE-2000-0630 Exploit

IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.

Jul 17, 2000 2 affected product(s) NVD
5.0
CVSS
76.0%
EPSS
⚡ 52.8
CVE-2000-0408 Exploit

IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.

May 11, 2000 2 affected product(s) NVD
5.0
CVSS
74.0%
EPSS
⚡ 52.2
CVE-2000-0305

Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.

May 19, 2000 6 affected product(s) NVD
7.8
CVSS
41.0%
EPSS
⚡ 43.5
CVE-2000-0402 Exploit

The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.

May 30, 2000 3 affected product(s) NVD
2.1
CVSS
78.5%
EPSS
⚡ 41.9
CVE-2000-0506

The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the "Linux kernel setuid/setcap vulnerability."

Jun 9, 2000 19 affected product(s) NVD
10.0
CVSS
4.4%
EPSS
⚡ 41.3
CVE-2000-0304

Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.

May 10, 2000 2 affected product(s) NVD
5.0
CVSS
51.7%
EPSS
⚡ 35.5
CVE-2000-0464

Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability.

May 17, 2000 4 affected product(s) NVD
7.6
CVSS
15.1%
EPSS
⚡ 34.9
CVE-2000-0631

An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability.

Jul 14, 2000 3 affected product(s) NVD
5.0
CVSS
48.4%
EPSS
⚡ 34.5
CVE-2000-0419

The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.

May 11, 2000 10 affected product(s) NVD
7.5
CVSS
14.2%
EPSS
⚡ 34.3
CVE-2000-0653

Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.

Jul 20, 2000 4 affected product(s) NVD
5.0
CVSS
47.4%
EPSS
⚡ 34.2
CVE-2000-0596

Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.

Jun 27, 2000 2 affected product(s) NVD
7.5
CVSS
13.0%
EPSS
⚡ 33.9
CVE-2000-0597

Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.

Jun 27, 2000 3 affected product(s) NVD
7.5
CVSS
9.6%
EPSS
⚡ 32.9
CVE-2000-0621

Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.

Jul 20, 2000 7 affected product(s) NVD
7.5
CVSS
5.9%
EPSS
⚡ 31.8
CVE-2000-0450

Vulnerability in bbd server in Big Brother System and Network Monitor allows an attacker to execute arbitrary commands.

May 18, 2000 4 affected product(s) NVD
7.5
CVSS
0.9%
EPSS
⚡ 30.3
CVE-2000-0533

Vulnerability in cvconnect in SGI IRIX WorkShop allows local users to overwrite arbitrary files.

Jun 20, 2000 1 affected product(s) NVD
7.2
CVSS
0.1%
EPSS
⚡ 28.8
CVE-2000-0372

Vulnerability in Caldera rmt command in the dump package 0.4b4 allows a local user to gain root privileges.

Jul 12, 2000 1 affected product(s) NVD
7.2
CVSS
0.1%
EPSS
⚡ 28.8
CVE-2000-0465

Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability.

May 17, 2000 4 affected product(s) NVD
5.1
CVSS
24.5%
EPSS
⚡ 27.8
CVE-2000-0404

The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability.

May 25, 2000 5 affected product(s) NVD
5.0
CVSS
24.3%
EPSS
⚡ 27.3
CVE-2000-0673

The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability.

Jul 27, 2000 3 affected product(s) NVD
5.0
CVSS
20.3%
EPSS
⚡ 26.1