Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
406 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 11% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP | 10/4/2007 | 16/6/2026 | Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file. | |
| Modificada | Alta (9.3) | 31% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 10/4/2007 | 16/6/2026 | Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption. | |
| Modificada | Alta (7.2) | 2.7% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 10/4/2007 | 16/6/2026 | The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which allows local users to gain privileges by modifying the "zero page"… | |
| Modificada | Media (6.6) | 2.1% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows VistaMicrosoft Windows XP | 4/4/2007 | 16/6/2026 | Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via a crafted Enhanced Metafile (EMF) image format file. | |
| Modificada | Alta (7.2) | 2.7% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows VistaMicrosoft Windows XP | 4/4/2007 | 16/6/2026 | Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images. | |
| Modificada | Alta (7.1) | 29% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 4/4/2007 | 16/6/2026 | Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-assisted remote attackers to cause a denial of service (possibly persistent restart) via a crafted Windows Metafile (WMF) image that causes an invalid dereference of an offset in a kernel structure, a… | |
| Modificada | Alta (9.3) | 73% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows VistaMicrosoft Windows XP | 30/3/2007 | 16/6/2026 | Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory… | |
| Modificada | Alta (9.3) | 55% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows VistaMicrosoft Windows XP+6 | 30/3/2007 | 16/6/2026 | Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416,… | |
| Modificada | Alta (7.5) | 15% | — | Microsoft Windows 2000Microsoft Windows 2003 Server | 26/3/2007 | 16/6/2026 | The default configuration of Microsoft Windows uses the Web Proxy Autodiscovery Protocol (WPAD) without static WPAD entries, which might allow remote attackers to intercept web traffic by registering a proxy server using WINS or DNS, then responding to WPAD requests, as demonstrated using Internet Explorer. NOTE: it… | |
| Modificada | Baja (3.6) | 1.3% | — | Microsoft Windows 2003 ServerMicrosoft Windows XP | 20/3/2007 | 16/6/2026 | \Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function. | |
| Modificada | Media (4.6) | 3.4% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows VistaMicrosoft Windows XP | 23/2/2007 | 16/6/2026 | The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST… | |
| Modificada | Alta (9.3) | 31% | — | Microsoft Learning EssentialsMicrosoft OfficeMicrosoft Windows 2000Microsoft Windows 2003 Server+1 | 13/2/2007 | 16/6/2026 | The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which… | |
| Modificada | Alta (7.6) | 25% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 13/2/2007 | 16/6/2026 | The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. | |
| Modificada | Alta (7.2) | 2.7% | — | Microsoft Windows 2003 ServerMicrosoft Windows XP | 13/2/2007 | 16/6/2026 | The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware." | |
| Modificada | Alta (9.3) | 37% | — | Microsoft Visual Studio .netMicrosoft Windows 2003 Server | 13/2/2007 | 16/6/2026 | The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer… | |
| Modificada | Alta (9.3) | 27% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 13/2/2007 | 16/6/2026 | The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters. | |
| Modificada | Alta (10) | 15% | — | Microsoft Windows 2003 Server | 31/12/2006 | 16/6/2026 | Unspecified vulnerability in the Bluetooth stack in Microsoft Windows Mobile Pocket PC edition allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors. | |
| Modificada | Alta (10) | 15% | — | Microsoft Windows 2003 Server | 31/12/2006 | 16/6/2026 | Unspecified vulnerability in the Bluetooth stack in Microsoft Windows allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors. | |
| Modificada | Media (6.9) | 3.4% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows VistaMicrosoft Windows XP | 22/12/2006 | 16/6/2026 | Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly… | |
| Modificada | Alta (7.2) | 1.8% | — | Microsoft Windows 2003 ServerMicrosoft Windows XP | 13/12/2006 | 16/6/2026 | The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest within an application, aka "File Manifest Corruption Vulnerability." | |
| Modificada | Media (6.8) | 28% | — | Microsoft Windows Media PlayerMicrosoft Windows 2003 ServerMicrosoft Windows XP | 13/12/2006 | 16/6/2026 | Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file. | |
| Modificada | Alta (10) | 53% | — | Microsoft Windows 2003 Server | 12/12/2006 | 16/6/2026 | Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability." | |
| Modificada | Alta (7.5) | 75% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 14/11/2006 | 16/6/2026 | Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability." | |
| Modificada | Media (5) | 35% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 14/11/2006 | 16/6/2026 | Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability." | |
| Modificada | Alta (7.5) | 41% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 14/11/2006 | 16/6/2026 | Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow. |