Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,996 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 316 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2005-0500 | Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in a titlebar for a script-initiated popup window, which could facilitate phishing attacks. | MEDIUM 5.0EPSS 10.7% | 2 May 2005 |
| CVE-2005-0491 | Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request. | EXPLOIT ×5 ✓HIGH 10.0EPSS 64.9% | 2 May 2005 |
| CVE-2005-0468 | Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more… | EXPLOIT ✓HIGH 7.5EPSS 27.1% | 2 May 2005 |
| CVE-2005-0455 | Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1 allows remote attackers to execute arbitrary code via a .SMIL… | EXPLOIT ×2 ✓MEDIUM 5.1EPSS 54.0% | 2 May 2005 |
| CVE-2005-0446 | Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure. | MEDIUM 5.0EPSS 41.1% | 2 May 2005 |
| CVE-2005-0439 | Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names. | EXPLOIT ✓HIGH 7.5EPSS 10.0% | 2 May 2005 |
| CVE-2005-0399 | Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a… | MEDIUM 5.1EPSS 15.1% | 2 May 2005 |
| CVE-2005-0353 | Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary code by sending a large amount of data to UDP port 5093. | EXPLOIT ×2 ✓HIGH 10.0EPSS 71.1% | 2 May 2005 |
| CVE-2005-0277 | Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the USER command or (2) an FTP command that contains a… | EXPLOIT ×3 ✓MEDIUM 5.0EPSS 61.9% | 2 May 2005 |
| CVE-2005-0260 | Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attackers to execute arbitrary code via a long packet to UDP port 41524, which is not properly handled in a recvfrom call. | EXPLOIT ✓HIGH 10.0EPSS 69.7% | 2 May 2005 |
| CVE-2005-0241 | The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls… | MEDIUM 5.0EPSS 69.7% | 2 May 2005 |
| CVE-2005-0211 | Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length… | HIGH 7.5EPSS 22.2% | 2 May 2005 |
| CVE-2005-0199 | Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length… | EXPLOIT ✓CRITICAL 9.8EPSS 18.8% | 2 May 2005 |
| CVE-2005-0173 | squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server. | HIGH 7.5EPSS 31.9% | 2 May 2005 |
| CVE-2005-0063 | The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML… | EXPLOIT ✓HIGH 7.5EPSS 47.6% | 2 May 2005 |
| CVE-2005-0059 | Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message. | EXPLOIT ×2 ✓HIGH 10.0EPSS 73.3% | 2 May 2005 |
| CVE-2005-0057 | The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow. | HIGH 7.5EPSS 41.3% | 2 May 2005 |
| CVE-2005-0056 | Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross… | MEDIUM 5.1EPSS 28.3% | 2 May 2005 |
| CVE-2005-0055 | Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory… | HIGH 7.5EPSS 36.8% | 2 May 2005 |
| CVE-2005-0054 | Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to… | MEDIUM 5.1EPSS 24.3% | 2 May 2005 |
| CVE-2005-0053 | Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability." | EXPLOIT ✓HIGH 7.5EPSS 59.8% | 2 May 2005 |
| CVE-2005-0051 | The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe… | HIGH 7.5EPSS 46.6% | 2 May 2005 |
| CVE-2005-0050 | The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and… | HIGH 10.0EPSS 46.7% | 2 May 2005 |
| CVE-2005-0049 | Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to… | MEDIUM 4.3EPSS 20.2% | 2 May 2005 |
| CVE-2005-0048 | Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP… | EXPLOIT ×3 ✓HIGH 7.5EPSS 38.6% | 2 May 2005 |
| CVE-2005-0045 | The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2)… | EXPLOIT ✓HIGH 7.5EPSS 70.3% | 2 May 2005 |
| CVE-2005-0044 | The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation… | HIGH 7.5EPSS 33.4% | 2 May 2005 |
| CVE-2005-0043 | Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files. | EXPLOIT ×2 ✓HIGH 7.5EPSS 69.0% | 2 May 2005 |
| CVE-2005-0033 | Buffer overflow in the code for recursion and glue fetching in BIND 8.4.4 and 8.4.5 allows remote attackers to cause a denial of service (crash) via queries that trigger the overflow in the q_usedns array that tracks nameservers and addresses. | MEDIUM 5.0EPSS 11.4% | 2 May 2005 |
| CVE-2005-0420 | Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application. | EXPLOIT ✓MEDIUM 5.8EPSS 25.6% | 27 April 2005 |
| CVE-2005-0416 | The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to execute arbitrary code via the AnimationHeaderBlock length field, which leads to a stack-based… | EXPLOIT ×2 ✓HIGH 7.5EPSS 41.0% | 27 April 2005 |
| CVE-2004-1488 | wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code. | EXPLOIT ✓MEDIUM 5.0EPSS 11.9% | 27 April 2005 |
| CVE-2005-1275 | Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value. | EXPLOIT ✓MEDIUM 5.0EPSS 13.9% | 25 April 2005 |
| CVE-2005-0684 | Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV… | EXPLOIT ✓HIGH 10.0EPSS 68.5% | 25 April 2005 |
| CVE-2005-0718 | Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory. | MEDIUM 5.0EPSS 12.5% | 14 April 2005 |
| CVE-2005-0129 | The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected. | EXPLOIT ✓HIGH 7.5EPSS 10.3% | 14 April 2005 |
| CVE-2005-1099 | Multiple buffer overflows in the HandleChild function in server.c in Greylisting daemon (GLD) 1.3 and 1.4, when GLD is listening on a network interface, allow remote attackers to execute arbitrary code. | EXPLOIT ×3 ✓HIGH 10.0EPSS 67.7% | 12 April 2005 |
| CVE-2005-0562 | GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width. | HIGH 7.5EPSS 23.2% | 12 April 2005 |
| CVE-2005-0555 | Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability." | EXPLOIT ✓HIGH 7.5EPSS 58.4% | 12 April 2005 |
| CVE-2004-0791 | Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench… | EXPLOIT ✓MEDIUM 5.0EPSS 20.3% | 12 April 2005 |
| CVE-2004-0790 | Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have… | EXPLOIT ×3 ✓MEDIUM 5.0EPSS 80.1% | 12 April 2005 |
| CVE-2005-0484 | Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log. | HIGH 7.5EPSS 10.8% | 30 March 2005 |
| CVE-2005-0478 | Multiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP request with a long User-Agent header or (2) a long argument to an arbitrary PHP script. | EXPLOIT ✓MEDIUM 5.0EPSS 66.5% | 30 March 2005 |
| CVE-2005-0509 | Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal… | MEDIUM 4.3EPSS 15.9% | 14 March 2005 |
| CVE-2005-0701 | Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.." (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename. | EXPLOIT ✓MEDIUM 5.0EPSS 18.1% | 7 March 2005 |
| CVE-2005-0688 | Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 47.4% | 5 March 2005 |
| CVE-2004-1037 | The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string. | EXPLOIT ×2 ✓HIGH 10.0EPSS 61.7% | 1 March 2005 |
| CVE-2004-1029 | The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load… | EXPLOIT ✓HIGH 9.3EPSS 17.0% | 1 March 2005 |
| CVE-2004-0990 | Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a… | EXPLOIT ✓HIGH 10.0EPSS 28.3% | 1 March 2005 |
| CVE-2004-0989 | Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy… | EXPLOIT ✓HIGH 10.0EPSS 21.7% | 1 March 2005 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.