Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

517 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.0%—Microsoft Windows 20006/10/200516/6/2026
The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.
ModificadaAlta (7.5)3.9%—Microsoft Windows 20006/10/200516/6/2026
Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection.
ModificadaAlta (7.5)46%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+210/8/200516/6/2026
Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to elevate privileges or execute arbitrary code via a crafted message.
ModificadaMedia (5)57%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP10/8/200516/6/2026
The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
ModificadaAlta (10)93%💥 ExploitMicrosoft Windows 2000Microsoft Windows XP10/8/200516/6/2026
Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.
ModificadaBaja (2.1)6.6%—Microsoft Windows 2000Microsoft Windows 2003 Server10/8/200516/6/2026
Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.
ModificadaAlta (7.5)55%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP10/8/200516/6/2026
Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
ModificadaBaja (3.6)1.7%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP10/8/200516/6/2026
Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
ModificadaAlta (7.2)1.8%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 95Microsoft Windows 98+327/7/200516/6/2026
Buffer overflow in a certain USB driver, as used on Microsoft Windows, allows attackers to execute arbitrary code.
ModificadaMedia (5)26%💥 ExploitMicrosoft Windows 2000Microsoft Windows XP19/7/200516/6/2026
netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."
ModificadaMedia (5)19%—Microsoft Windows 2000Microsoft Windows NT11/7/200516/6/2026
Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.
ModificadaAlta (7.5)25%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 2003 ServerMicrosoft Windows 98+314/6/200516/6/2026
Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.
ModificadaAlta (10)47%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows XP14/6/200516/6/2026
Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.
ModificadaMedia (5.1)13%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 2003 ServerMicrosoft Windows 98+314/6/200516/6/2026
Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.
ModificadaAlta (7.5)59%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP14/6/200516/6/2026
Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."
ModificadaAlta (7.5)27%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP13/6/200516/6/2026
Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the function to overwrite previously freed memory, as demonstrated using a…
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
ModificadaAlta (7.2)1.8%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+22/5/200516/6/2026
The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.
ModificadaMedia (5)17%💥 ExploitMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows ME2/5/200516/6/2026
The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View constructs a mailto: link for the preview pane when the user selects…
ModificadaAlta (7.5)33%—Microsoft Exchange ServerMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98+32/5/200516/6/2026
The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."
ModificadaMedia (5)33%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98seMicrosoft Windows NT+12/5/200516/6/2026
The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the correct sequence number but the wrong Acknowledgement number, which generates a large number of "keep alive" packets. NOTE: some followups indicate that this issue could not…
ModificadaAlta (7.5)41%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+22/5/200516/6/2026
The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.
ModificadaMedia (5)68%💥 ExploitMicrosoft Windows 20002/5/200516/6/2026
The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."
ModificadaAlta (7.2)1.8%—Microsoft Windows 2000Microsoft Windows XP2/5/200516/6/2026
Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash drive. NOTE: this issue has been disputed in a followup post.
ModificadaAlta (7.5)70%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP2/5/200516/6/2026
The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as…
Orbitaley — Vulnerabilidades