← Vulnerability feed

Vulnerability record · CVE-2000-0153 · published 26 March 1999

CVE-2000-0153: Microsoft frontpage vulnerability

Microsoft · Frontpage

FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack.

5.0 CVSS 2.0 Medium EPSS 14% · top 3.6%
5.0CVSS 2.0 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-0153 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed9.3CVE-2006-3877Microsoft access code injection vulnerabilityUnspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-a…EPSS 13%9.3CVE-2004-0200Microsoft GDI+ JPEG parsing buffer overflow via crafted imageThe JPEG parsing engine in Microsoft GDI+ (GDIPlus.dll) contains a buffer overflow: a small JPEG COM field length is normalized to a large integer le…EPSS 49%analysed7.5CVE-2008-3068Microsoft access vulnerabilityMicrosoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) …EPSS 17%7.5CVE-2004-0573Microsoft frontpage vulnerabilityBuffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remo…EPSS 42%7.5CVE-2000-0746Microsoft frontpage vulnerabilityVulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to em…EPSS 10%7.5CVE-2000-0419Microsoft access vulnerabilityThe Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show …EPSS 21%7.5CVE-2000-0256Microsoft frontpage vulnerabilityBuffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise a…EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2000-0153), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.