Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
455 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 29% | — | Microsoft Internet ExplorerMicrosoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows XP+3 | 31/3/2010 | 16/6/2026 | Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 24% | — | Microsoft Internet ExplorerMicrosoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows XP+3 | 31/3/2010 | 16/6/2026 | Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Race Condition Memory Corruption Vulnerability." | |
| Modificada | Media (6.5) | 29% | — | Microsoft Internet ExplorerMicrosoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows XP+3 | 31/3/2010 | 16/6/2026 | Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure Vulnerability." | |
| Modificada | Alta (9.3) | 34% | — | Microsoft Internet ExplorerMicrosoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows XP+3 | 31/3/2010 | 16/6/2026 | Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability." | |
| Modificada | Alta (7.6) | 25% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows XP | 3/3/2010 | 16/6/2026 | Stack-based buffer overflow in VBScript in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, might allow user-assisted remote attackers to execute arbitrary code via a long string in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code… | |
| Modificada | Alta (7.6) | 87% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows XP | 3/3/2010 | 16/6/2026 | vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file… | |
| Modificada | Alta (7.2) | 2.7% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 10/2/2010 | 16/6/2026 | Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vulnerability." | |
| Modificada | Media (6.3) | 16% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008 | 10/2/2010 | 16/6/2026 | The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a… | |
| Modificada | Alta (9.3) | 48% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP | 10/2/2010 | 16/6/2026 | Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability." | |
| Modificada | Alta (9.3) | 8.6% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP | 10/2/2010 | 16/6/2026 | The SMB client implementation in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate response fields, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted response, aka "SMB Client Pool Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Internet ExplorerMicrosoft Windows Server 2003Microsoft Windows XPMicrosoft Windows Server 2008+2 | 4/2/2010 | 16/6/2026 | Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving the product's use of text/html as the default content type for files that… | |
| Modificada | Alta (9.3) | 34% | 💥 Exploit | Microsoft Internet ExplorerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+4 | 22/1/2010 | 16/6/2026 | The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL… | |
| Modificada | Alta (10) | 22% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 9/12/2009 | 16/6/2026 | The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to… | |
| Modificada | Alta (9.3) | 26% | — | Microsoft Internet ExplorerMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP+3 | 9/12/2009 | 16/6/2026 | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability… | |
| Modificada | Alta (9.3) | 25% | — | Microsoft Internet ExplorerMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP+3 | 9/12/2009 | 16/6/2026 | Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability." | |
| Modificada | Alta (8.1) | 21% | — | Microsoft Internet ExplorerMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP+3 | 9/12/2009 | 16/6/2026 | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability… | |
| Modificada | Alta (9) | 17% | — | Microsoft Windows Server 2003Microsoft Windows Server 2008 | 9/12/2009 | 16/6/2026 | Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS… | |
| Modificada | Media (6.9) | 1.3% | — | Microsoft Windows Server 2003Microsoft Windows Server 2008 | 9/12/2009 | 16/6/2026 | The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same… | |
| Modificada | Alta (9.3) | 31% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XPMicrosoft Office Converter Pack+3 | 9/12/2009 | 16/6/2026 | Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with an invalid number of property names in the… | |
| Modificada | Alta (9.3) | 23% | — | Microsoft Internet ExplorerMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP+3 | 14/10/2009 | 16/6/2026 | Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a… | |
| Modificada | Alta (9.3) | 23% | — | Microsoft Internet ExplorerMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP+3 | 14/10/2009 | 16/6/2026 | Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a… | |
| Modificada | Alta (8.1) | 20% | — | Microsoft Internet ExplorerMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP+3 | 14/10/2009 | 16/6/2026 | Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Component Handling Vulnerability." | |
| Modificada | Alta (9.3) | 23% | — | Microsoft Windows 2000Microsoft Windows Media Format RuntimeMicrosoft Windows Media PlayerMicrosoft Windows XP+3 | 14/10/2009 | 16/6/2026 | Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly initialize unspecified functions within compressed audio files, which allows remote attackers to execute arbitrary code via (1) a crafted media file or (2)… | |
| Modificada | Media (4.9) | 1.8% | — | Microsoft Windows Server 2003 | 14/10/2009 | 16/6/2026 | The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition occurs, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability." | |
| Modificada | Alta (7.1) | 1.3% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 14/10/2009 | 16/6/2026 | The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows… |