Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 491 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
406 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 4.1% | — | Microsoft Windows 2000Microsoft Windows 2003 Server | 12/6/2008 | 16/6/2026 | The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability." | |
| Modificada | Alta (9.3) | 30% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 8/4/2008 | 16/6/2026 | The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (9.3) | 57% | 💥 Exploit | Microsoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Vista+1 | 8/4/2008 | 16/6/2026 | Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow Vulnerability." | |
| Modificada | Alta (7.2) | 6.8% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows Vista+1 | 8/4/2008 | 16/6/2026 | Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows local users to execute arbitrary code via unknown vectors related to improper input validation. NOTE: it was later reported that one affected function is NtUserFnOUTSTRING… | |
| Modificada | Alta (8.1) | 57% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows Vista+1 | 8/4/2008 | 16/6/2026 | Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap… | |
| Modificada | Alta (9.3) | 31% | — | Microsoft Internet ExplorerMicrosoft Windows-ntMicrosoft Windows 2003 ServerMicrosoft Windows Vista+1 | 8/4/2008 | 16/6/2026 | The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption. | |
| Modificada | Media (6.8) | 29% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 12/2/2008 | 16/6/2026 | Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request. | |
| Modificada | Alta (7.2) | 2.6% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 8/1/2008 | 16/6/2026 | Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request. | |
| Modificada | Alta (9.3) | 49% | — | Microsoft Windows 2003 ServerMicrosoft Windows VistaMicrosoft Windows XP | 8/1/2008 | 16/6/2026 | Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2… | |
| Modificada | Alta (7.1) | 32% | — | Microsoft Home ServerMicrosoft Small Business ServerMicrosoft Windows 2000Microsoft Windows 2003 Server+2 | 8/1/2008 | 16/6/2026 | The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability." | |
| Modificada | Alta (9.3) | 28% | 💥 Exploit | Microsoft JETMicrosoft OfficeMicrosoft Windows 2000Microsoft Windows 2003 Server+2 | 20/11/2007 | 16/6/2026 | Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be… | |
| Modificada | Media (6.4) | 52% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2003 | 14/11/2007 | 16/6/2026 | The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors. | |
| Modificada | Alta (7.8) | 43% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows VistaMicrosoft Windows XP | 9/10/2007 | 16/6/2026 | rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that… | |
| Modificada | Alta (7.1) | 23% | 💥 Exploit | Microsoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows VistaMicrosoft Windows XP+1 | 27/9/2007 | 16/6/2026 | Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file with a large tEXt chunk that possibly triggers an integer overflow in PNG chunk size handling, as demonstrated by badlycrafted.png. | |
| Modificada | Media (6.9) | 2.4% | — | Microsoft Windows Services FOR UnixMicrosoft Windows 2003 ServerMicrosoft Windows Vista | 12/9/2007 | 16/6/2026 | Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain setuid binary files." | |
| Modificada | Alta (9.3) | 52% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows XP | 14/8/2007 | 16/6/2026 | Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (10) | 39% | — | Microsoft Windows 2000Microsoft Windows 2003 Server | 10/7/2007 | 16/6/2026 | The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible… | |
| Modificada | Media (5) | 25% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 27/6/2007 | 16/6/2026 | Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block. | |
| Modificada | Alta (9.3) | 32% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 12/6/2007 | 16/6/2026 | Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function. | |
| Modificada | Alta (9.3) | 13% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 12/6/2007 | 16/6/2026 | Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake. | |
| Modificada | Alta (7.1) | 28% | — | Microsoft Windows 2003 ServerMicrosoft Windows XPMicrosoft Internet ExplorerMicrosoft Windows 2000+2 | 6/6/2007 | 16/6/2026 | Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code or perform other actions upon a page transition, with the permissions of the old page and the… | |
| Modificada | Baja (1.8) | 1.6% | — | Microsoft Windows 2003 Server | 4/6/2007 | 16/6/2026 | Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names. | |
| Modificada | Media (4.3) | 36% | 💥 Exploit | Microsoft Sharepoint ServerMicrosoft Sharepoint ServicesMicrosoft Windows 2003 | 9/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx. | |
| Modificada | Alta (9.3) | 17% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XPAvaya Media Server+3 | 30/4/2007 | 16/6/2026 | Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source. | |
| Modificada | Alta (10) | 78% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 Server | 13/4/2007 | 16/6/2026 | Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences. |