Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

517 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.5%—Microsoft Windows 200031/12/200216/6/2026
Windows 2000 Terminal Services, when using the disconnect feature of the client, does not properly lock itself if it is left idle until the screen saver activates and the user disconnects, which could allow attackers to gain administrator privileges.
ModificadaAlta (10)15%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+423/12/200216/6/2026
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.
ModificadaMedia (5)14%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+423/12/200216/6/2026
Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."
ModificadaAlta (7.5)16%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+423/12/200216/6/2026
The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet.
ModificadaMedia (5)15%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+423/12/200216/6/2026
Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.
ModificadaMedia (5)5.4%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows XP23/12/200216/6/2026
The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy…
ModificadaMedia (4.6)2.8%—Microsoft Windows 2000Microsoft Windows NT12/11/200216/6/2026
The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.
ModificadaMedia (4.6)2.4%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2000 Terminal Services4/11/200216/6/2026
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling…
ModificadaAlta (7.5)51%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows XP28/10/200216/6/2026
Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.
ModificadaMedia (5)28%—Microsoft Windows 200022/10/200216/6/2026
Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.
ModificadaMedia (5)22%—Microsoft .net Windows ServerMicrosoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows NT+111/10/200216/6/2026
Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."
ModificadaMedia (5)16%—Microsoft .net Windows ServerMicrosoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows XP11/10/200216/6/2026
The Remote Data Protocol (RDP) version 5.1 in Microsoft Windows XP allows remote attackers to cause a denial of service (crash) when Remote Desktop is enabled via a PDU Confirm Active data packet that does not set the Pattern BLT command, aka "Denial of Service in Remote Desktop."
ModificadaAlta (7.5)14%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 98Microsoft Windows 98se+310/10/200216/6/2026
The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via…
ModificadaAlta (7.5)18%—Microsoft Frontpage Server ExtensionsMicrosoft Windows 2000Microsoft Windows XP10/10/200216/6/2026
Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request.
ModificadaAlta (7.5)31%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 98Microsoft Windows 98se+310/10/200216/6/2026
Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long…
ModificadaMedia (5)6.5%—Microsoft Windows 2000Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows ME+24/10/200216/6/2026
Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.
ModificadaMedia (6.8)16%💥 ExploitMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows ME+54/10/200216/6/2026
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate…
ModificadaAlta (7.5)26%💥 ExploitMicrosoft Windows 2000Microsoft Windows NTMicrosoft Windows XP24/9/200216/6/2026
Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share…
ModificadaMedia (5.5)1.2%—Microsoft Windows 2000Microsoft Windows NT5/9/200216/6/2026
NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file.
ModificadaAlta (7.2)2.2%—Microsoft Windows 2000Microsoft Windows 2000 Terminal Services5/9/200216/6/2026
A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code.
ModificadaCrítica (9.8)58%—FreebsdOpenbsdSUN SolarisSunos+312/8/200216/6/2026
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
ModificadaAlta (7.5)26%💥 ExploitMicrosoft Windows HelpMicrosoft Windows 200012/8/200216/6/2026
Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter.
ModificadaMedia (4.6)4.7%—Microsoft Windows 200026/7/200216/6/2026
Microsoft Windows 2000 allows local users to bypass the policy that prohibits reusing old passwords by changing the current password before it expires, which does not enable the check for previous passwords.
ModificadaAlta (7.5)12%—Microsoft Windows 2000 Terminal Services26/7/200216/6/2026
Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass…
ModificadaAlta (7.2)2.8%—Microsoft Windows 2000Microsoft Windows NTMicrosoft Windows XP3/7/200216/6/2026
Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.
Orbitaley — Vulnerabilidades