Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

404 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)29%—Microsoft IEMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP12/9/200616/6/2026
Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP…
ModificadaMedia (4.3)25%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP12/9/200616/6/2026
Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
ModificadaAlta (7.5)21%💥 ExploitMicrosoft IEMicrosoft Windows 2003 Server31/8/200616/6/2026
Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
ModificadaBaja (2.6)24%💥 ExploitMicrosoft Windows 2003 ServerMicrosoft Windows XP10/8/200616/6/2026
Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
ModificadaAlta (10)57%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP9/8/200616/6/2026
Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka "Winsock Hostname Vulnerability."
ModificadaAlta (10)85%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP9/8/200616/6/2026
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.
ModificadaAlta (10)62%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP9/8/200616/6/2026
Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response. NOTE: while MS06-041 implies that there is a single issue, there are multiple vectors, and likely multiple vulnerabilities,…
ModificadaAlta (7.6)24%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP9/8/200616/6/2026
Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 and 2003 SP1, allows remote attackers to execute arbitrary code via unspecified vectors involving unhandled exceptions, memory resident applications, and incorrectly "unloading chained exception."
ModificadaAlta (7.8)75%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP31/7/200616/6/2026
The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function,…
ModificadaMedia (5)25%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP27/7/200616/6/2026
Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by…
ModificadaAlta (7.5)61%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP11/7/200616/6/2026
Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on…
ModificadaMedia (5.4)6.9%—Microsoft Windows 2003 ServerMicrosoft Windows XP6/7/200616/6/2026
Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url file with an InternetShortcut tag containing a long URL and a large number of "file:" specifiers.
ModificadaAlta (9.3)54%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP13/6/200616/6/2026
Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.
ModificadaMedia (6.8)29%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+213/6/200616/6/2026
Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.
ModificadaAlta (7.5)70%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP13/6/200616/6/2026
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."
ModificadaMedia (6.8)35%—Microsoft IEMicrosoft Internet ExplorerMicrosoft Windows 2003 ServerMicrosoft Windows XP13/6/200616/6/2026
Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
ModificadaMedia (5.5)1.7%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP13/6/200616/6/2026
The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB…
ModificadaAlta (7.5)23%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP13/6/200616/6/2026
Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption…
ModificadaAlta (7.5)31%—Microsoft Distributed Transaction CoordinatorMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NT+110/5/200616/6/2026
Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode,…
ModificadaMedia (5)30%—Microsoft Distributed Transaction CoordinatorMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NT+110/5/200616/6/2026
Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the…
ModificadaMedia (5.1)25%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+212/4/200616/6/2026
Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."
ModificadaMedia (5.1)7.1%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP3/4/200616/6/2026
Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to execute arbitrary code via crafted embedded image data in a .hlp file.
ModificadaAlta (7.8)60%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NT3/3/200616/6/2026
The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic…
ModificadaAlta (9.3)50%💥 ExploitMicrosoft Windows Media PlayerMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98+314/2/200616/6/2026
Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but…
ModificadaMedia (6.5)35%—Microsoft Windows 2003 ServerMicrosoft Windows XP14/2/200616/6/2026
Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.
Orbitaley — Vulnerabilidades