Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
517 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Windows 2000 | 31/12/2002 | 16/6/2026 | Windows 2000 Terminal Services, when using the disconnect feature of the client, does not properly lock itself if it is left idle until the screen saver activates and the user disconnects, which could allow attackers to gain administrator privileges. | |
| Modificada | Alta (10) | 15% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+4 | 23/12/2002 | 16/6/2026 | Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail. | |
| Modificada | Media (5) | 14% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+4 | 23/12/2002 | 16/6/2026 | Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability." | |
| Modificada | Alta (7.5) | 16% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+4 | 23/12/2002 | 16/6/2026 | The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet. | |
| Modificada | Media (5) | 15% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+4 | 23/12/2002 | 16/6/2026 | Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error. | |
| Modificada | Media (5) | 5.4% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows XP | 23/12/2002 | 16/6/2026 | The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy… | |
| Modificada | Media (4.6) | 2.8% | — | Microsoft Windows 2000Microsoft Windows NT | 12/11/2002 | 16/6/2026 | The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs. | |
| Modificada | Media (4.6) | 2.4% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2000 Terminal Services | 4/11/2002 | 16/6/2026 | NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling… | |
| Modificada | Alta (7.5) | 51% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows XP | 28/10/2002 | 16/6/2026 | Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data. | |
| Modificada | Media (5) | 28% | — | Microsoft Windows 2000 | 22/10/2002 | 16/6/2026 | Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests. | |
| Modificada | Media (5) | 22% | — | Microsoft .net Windows ServerMicrosoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows NT+1 | 11/10/2002 | 16/6/2026 | Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol." | |
| Modificada | Media (5) | 16% | — | Microsoft .net Windows ServerMicrosoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows XP | 11/10/2002 | 16/6/2026 | The Remote Data Protocol (RDP) version 5.1 in Microsoft Windows XP allows remote attackers to cause a denial of service (crash) when Remote Desktop is enabled via a PDU Confirm Active data packet that does not set the Pattern BLT command, aka "Denial of Service in Remote Desktop." | |
| Modificada | Alta (7.5) | 14% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 98Microsoft Windows 98se+3 | 10/10/2002 | 16/6/2026 | The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via… | |
| Modificada | Alta (7.5) | 18% | — | Microsoft Frontpage Server ExtensionsMicrosoft Windows 2000Microsoft Windows XP | 10/10/2002 | 16/6/2026 | Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request. | |
| Modificada | Alta (7.5) | 31% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 98Microsoft Windows 98se+3 | 10/10/2002 | 16/6/2026 | Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long… | |
| Modificada | Media (5) | 6.5% | — | Microsoft Windows 2000Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows ME+2 | 4/10/2002 | 16/6/2026 | Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML. | |
| Modificada | Media (6.8) | 16% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows ME+5 | 4/10/2002 | 16/6/2026 | The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate… | |
| Modificada | Alta (7.5) | 26% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows NTMicrosoft Windows XP | 24/9/2002 | 16/6/2026 | Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share… | |
| Modificada | Media (5.5) | 1.2% | — | Microsoft Windows 2000Microsoft Windows NT | 5/9/2002 | 16/6/2026 | NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file. | |
| Modificada | Alta (7.2) | 2.2% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal Services | 5/9/2002 | 16/6/2026 | A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code. | |
| Modificada | Crítica (9.8) | 58% | — | FreebsdOpenbsdSUN SolarisSunos+3 | 12/8/2002 | 16/6/2026 | Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd. | |
| Modificada | Alta (7.5) | 26% | 💥 Exploit | Microsoft Windows HelpMicrosoft Windows 2000 | 12/8/2002 | 16/6/2026 | Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter. | |
| Modificada | Media (4.6) | 4.7% | — | Microsoft Windows 2000 | 26/7/2002 | 16/6/2026 | Microsoft Windows 2000 allows local users to bypass the policy that prohibits reusing old passwords by changing the current password before it expires, which does not enable the check for previous passwords. | |
| Modificada | Alta (7.5) | 12% | — | Microsoft Windows 2000 Terminal Services | 26/7/2002 | 16/6/2026 | Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass… | |
| Modificada | Alta (7.2) | 2.8% | — | Microsoft Windows 2000Microsoft Windows NTMicrosoft Windows XP | 3/7/2002 | 16/6/2026 | Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry. |