Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
517 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 57% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 3/11/2004 | 16/6/2026 | Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer." | |
| Modificada | Alta (10) | 47% | 💥 Exploit | Microsoft Internet ExplorerMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows ME+1 | 3/11/2004 | 16/6/2026 | Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba. | |
| Modificada | Baja (2.1) | 1.8% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows NT+1 | 3/11/2004 | 16/6/2026 | "Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the… | |
| Modificada | Alta (10) | 64% | 💥 Exploit | Microsoft Exchange ServerMicrosoft Windows 2000Microsoft Windows NTMicrosoft Windows Server 2003 | 3/11/2004 | 16/6/2026 | The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer,"… | |
| Modificada | Alta (7.5) | 75% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows NT+1 | 3/11/2004 | 16/6/2026 | Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer… | |
| Modificada | Alta (7.2) | 2.4% | — | Microsoft Windows 2000 | 31/8/2004 | 16/6/2026 | Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future. | |
| Analizada | Media (5) | 80% | 💥 Exploit | Juniper JunosMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows 98se+8 | 18/8/2004 | 16/6/2026 | TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP. | |
| Modificada | Media (5) | 34% | — | Avaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+14 | 18/8/2004 | 16/6/2026 | Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by… | |
| Modificada | Alta (10) | 45% | — | Avaya Ip600 Media ServersAvaya Definity ONE Media ServerAvaya S8100Avaya Modular Messaging Message Storage Server+7 | 6/8/2004 | 16/6/2026 | Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041. | |
| Modificada | Alta (10) | 64% | 💥 Exploit | Avaya Ip600 Media ServersMicrosoft IEAvaya Definity ONE Media ServerAvaya S8100+4 | 6/8/2004 | 16/6/2026 | Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share. | |
| Modificada | Media (5) | 26% | — | Microsoft DirectxMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98+3 | 6/8/2004 | 16/6/2026 | IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet. | |
| Modificada | Alta (7.8) | 20% | 💥 Exploit | Microsoft Windows 2000 | 6/8/2004 | 16/6/2026 | Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and… | |
| Analizada | Alta (7.8) | 7.2% | ⚠ Explotación activa💥 Exploit | Microsoft InterixMicrosoft Windows 2000Microsoft Windows NT | 6/8/2004 | 16/6/2026 | The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow. | |
| Modificada | Alta (10) | 4.8% | — | Microsoft Windows 2000 | 6/8/2004 | 16/6/2026 | Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain. | |
| Modificada | Alta (7.5) | 11% | — | Microsoft Windows 2000 | 27/7/2004 | 16/6/2026 | The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel. | |
| Modificada | Alta (7.2) | 26% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows NT | 1/6/2004 | 16/6/2026 | The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory. | |
| Modificada | Media (5) | 32% | — | Microsoft Windows 2000 | 1/6/2004 | 16/6/2026 | Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message. | |
| Modificada | Alta (7.5) | 33% | — | Microsoft Windows 2000Microsoft Windows NTMicrosoft Windows XP | 1/6/2004 | 16/6/2026 | Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.2) | 22% | — | Microsoft Windows 2000Microsoft Windows NT | 1/6/2004 | 16/6/2026 | The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code. | |
| Modificada | Alta (7.5) | 30% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+3 | 1/6/2004 | 16/6/2026 | Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Baja (2.6) | 22% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP | 1/6/2004 | 16/6/2026 | The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability." | |
| Modificada | Media (5) | 38% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 1/6/2004 | 16/6/2026 | An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field. | |
| Modificada | Alta (7.6) | 25% | — | Microsoft Windows 2000Microsoft Windows NTMicrosoft Windows XP | 1/6/2004 | 16/6/2026 | Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image. | |
| Modificada | Alta (7.5) | 81% | 💥 Exploit | Microsoft NetmeetingMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98+3 | 1/6/2004 | 16/6/2026 | Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake… | |
| Modificada | Alta (7.2) | 26% | 💥 Exploit | Microsoft Windows 2000 | 1/6/2004 | 16/6/2026 | The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window,… |