Results host1.domain.com
Host type:
Windows 2000 SP1
Netbios Name: HOST1
MAC address: 00:80:5F:92:56:C4
Subnet:
172.16.0
Scanning level: heavy
Last scan: Fri Sep 8 14:49:33 2006
DNS
server
IMAP
server
POP
server
SMB
server
SMTP
server
SNMP
server
WWW
server
WWW (Secure)
server
WWW (non-standard port 8080)
server
47 other services (
show all services
)
Scan this host
Show excluded records
Confirmed Vulnerability
Inferred Vulnerability
Included Vulnerability
Excluded Vulnerability
Vulnerability information: (22 Red; 30 Yellow; 36 Brown)
Vulnerability
CVE
Windows Plug and Play vulnerability
CVE-2005-1983
EXPLOIT
Windows Plug and Play privilege elevation
CVE-2005-2120
MS Site Server default account
CVE-2002-1769
CVE-2002-2073
CVE-2002-2081
excessive null session access
CVE-2000-1200
null session access using alternate pipes
CVE-2005-2150
AxWebRemoveCtrl ActiveX control enabled
CVE-2005-3693
CodeSupport ActiveX control enabled
CVE-2005-3650
Guessed password to windows account (foobar:foobar)
password complexity policy disabled
CVE-1999-0535
weak account lockout policy (0)
CVE-1999-0582
weak minimum password age policy (0 days)
CVE-1999-0535
weak minimum password length policy (0)
CVE-1999-0535
weak password history policy (0)
CVE-1999-0535
vulnerable WinZip version: 8.0
CVE-2001-0449
CVE-2004-1465
last user name shown in login box
CVE-1999-0592
Folder traversal in IIS (Double Decoding)
CVE-2001-0333
EXPLOIT
Folder traversal in IIS (Unicode Translation)
CVE-2000-0884
EXPLOIT
vulnerabilities in IIS 5
CVE-2000-0770
CVE-2001-0151
CVE-2001-0241
EXPLOIT
CVE-2001-0500
CVE-2001-0507
CVE-2002-0869
CVE-2002-1180
CVE-2002-1181
CVE-2002-1182
CVE-2003-0223
CVE-2003-0224
CVE-2003-0225
CVE-2003-0226
Windows telephony service vulnerability
CVE-2005-0058
EXPLOIT
guessable read community string
CVE-1999-0516
CVE-1999-0517
vulnerability in Windows Media Services (nsiislog.dll)
CVE-2003-0227
CVE-2003-0349
SNMP is enabled and may be vulnerable
CVE-1999-0615
CVE-2002-0012
CVE-2002-0013
CVE-2002-0053
CVE-2002-0796
CVE-2002-0797
Possible ODBC RDS Vulnerability
CVE-1999-1011
CVE-2002-1142
chargen could be used in UDP bomb
CVE-1999-0103
Windows DNS server allows cache poisoning
CVE-2001-1452
Internet Explorer COM object memory corruption
CVE-2005-2127
Internet Explorer Create Text Range code injection
CVE-2006-1185
CVE-2006-1186
CVE-2006-1188
CVE-2006-1189
CVE-2006-1190
CVE-2006-1191
CVE-2006-1192
CVE-2006-1245
CVE-2006-1359
EXPLOIT
CVE-2006-1388
Internet Explorer JPEG buffer overflow
CVE-2005-1988
CVE-2005-1989
CVE-2005-1990
EXPLOIT
Internet Explorer JS stack overflow
CVE-2006-0753
CVE-2006-0830
Internet Explorer JavaScript vulnerability
CVE-2005-1790
EXPLOIT
CVE-2005-2829
CVE-2005-2830
CVE-2005-2831
Internet Explorer PNG buffer overflow
CVE-2002-0648
CVE-2005-1211
Internet Explorer URL parsing buffer overflow
CVE-2005-0553
EXPLOIT
CVE-2005-0554
CVE-2005-0555
EXPLOIT
Internet Explorer WMF handling vulnerability
CVE-2006-0020
Internet Explorer Shell.Explorer object enabled
CVE-2004-0985
Javaprxy.dll access through Internet Explorer
CVE-2005-2087
EXPLOIT
Run key allows write access
CVE-1999-0589
Uninstall key allows write access
CVE-1999-0589
vulnerability in License Logging Service
CVE-2005-0050
pop receives password in clear
MailEnable HTTPMail vulnerability
CVE-2005-1348
EXPLOIT
CVE-2005-2222
CVE-2006-1338
possible vulnerability in MailEnable Enterprise IMAP 1.04
CVE-2005-1014
CVE-2005-1015
CVE-2005-2278
EXPLOIT
CVE-2005-3155
EXPLOIT
CVE-2005-3690
EXPLOIT
CVE-2005-3691
CVE-2005-3813
CVE-2005-3993
CVE-2005-4402
CVE-2005-4456
CVE-2005-4457
CVE-2006-0504
possible vulnerability in MailEnable Enterprise POP3 1.04
CVE-2006-1337
possible vulnerability in MailEnable Enterprise POP3 1.04
CVE-2006-1337
possible vulnerability in MailEnable POP3 0
MailEnable Enterprise 1.04 may be vulnerable
CVE-2005-1013
CVE-2005-1781
EXPLOIT
CVE-2005-2223
Web server allows cross-site tracing
Password never expires for user LDAP_Anonymous
Password never expires for user foobar
Worm detected (Code Red II)
possible vulnerability in PPTP service
CVE-2002-1214
TCP reset using approximate sequence number
CVE-2004-0230
non-administrative users can act as part of the operating system
CVE-1999-0534
non-administrative users can bypass traverse checking
CVE-1999-0534
non-administrative users can create token object
CVE-1999-0534
MS FrontPage Server Extension Vulnerability: /_vti_bin/shtml.dll
CVE-2003-0824
MS FrontPage Server Extension Vulnerability: remote debug
CVE-2003-0822
EXPLOIT
Windows 2000 ASN1 buffer overflow
CVE-2003-0818
Windows 2000 RPC buffer overflow
CVE-2003-0352
EXPLOIT
Windows SMB Transaction response buffer overflow
CVE-2005-0045
Windows TCP/IP vulnerabilities
CVE-2004-0230
CVE-2004-0790
CVE-2004-1060
CVE-2005-0048
CVE-2005-0688
RPC runtime library vulnerability
CVE-2003-0807
CVE-2003-0813
CVE-2004-0116
CVE-2004-0124
Windows COM+ command execution vulnerability
CVE-2005-1978
CVE-2005-1979
CVE-2005-1980
CVE-2005-2119
Windows SMB input validation vulnerability
CVE-2005-1206
Windows WMF gdi32.dll vulnerability
CVE-2005-4560
EXPLOIT
DirectShow buffer overflow
CVE-2005-2128
HTML Application Host vulnerability in Windows shell
CVE-2005-0063
Microsoft Color Management Module buffer overflow
CVE-2005-1219
EXPLOIT
Microsoft Data Access Component vulnerability
CVE-2006-0003
EXPLOIT
Windows DHTML Editing Component vulnerability
CVE-2004-1319
Windows Explorer COM object command execution
CVE-2004-2289
CVE-2006-0012
Windows Hyperlink Object Library buffer overflow
CVE-2005-0057
Windows Media Player plug-in EMBED vulnerability
CVE-2006-0005
EXPLOIT
Windows Web Fonts vulnerability
CVE-2006-0010
Windows shortcut file command execution
CVE-2005-2117
CVE-2005-2118
CVE-2005-2122
Windows Kernel privilege elevation vulnerability
CVE-2005-2827
Client Service for Netware vulnerability
CVE-2005-1985
Collaboration Data Objects vulnerability
CVE-2005-1987
FTP Client vulnerability
CVE-2005-2126
Jet Database Engine input validation problems
CVE-2005-0944
EXPLOIT