Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
455 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 14/10/2009 | 16/6/2026 | Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application that triggers an incorrect truncation of a 64-bit integer to a 32-bit integer, aka "Windows Kernel… | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+2 | 14/10/2009 | 16/6/2026 | Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509… | |
| Modificada | Alta (9.3) | 23% | — | Microsoft Windows 2000Microsoft .net FrameworkMicrosoft Windows Server 2003Microsoft Windows Server 2008+3 | 14/10/2009 | 16/6/2026 | The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted… | |
| Modificada | Alta (8.8) | 37% | 💥 Exploit | Microsoft Internet ExplorerMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP+3 | 14/10/2009 | 16/6/2026 | Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 27% | — | Microsoft Windows 2000Microsoft Windows Media Format RuntimeMicrosoft Windows Media PlayerMicrosoft Windows XP+3 | 14/10/2009 | 16/6/2026 | Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted audio file that uses the Windows Media… | |
| Modificada | Alta (9.3) | 26% | — | Microsoft Windows 2000Microsoft .net FrameworkMicrosoft Windows Server 2003Microsoft Windows Server 2008+3 | 14/10/2009 | 16/6/2026 | Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application,… | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Windows 2000Microsoft .net FrameworkMicrosoft Windows Server 2003Microsoft Windows Server 2008+3 | 14/10/2009 | 16/6/2026 | Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET… | |
| Modificada | Alta (9.3) | 26% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP | 8/9/2009 | 16/6/2026 | The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers "system state" corruption, aka "DHTML Editing Component ActiveX Control… | |
| Modificada | Alta (8.5) | 16% | — | Microsoft Windows Media Format RuntimeMicrosoft Windows 2000Microsoft Windows XPMicrosoft Windows Server 2003+4 | 8/9/2009 | 16/6/2026 | Microsoft Windows Media Format Runtime 9.0, 9.5, and 11; and Microsoft Media Foundation on Windows Vista Gold, SP1, and SP2 and Server 2008; allows remote attackers to execute arbitrary code via an MP3 file with crafted metadata that triggers memory corruption, aka "Windows Media Playback Memory Corruption… | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Windows Media Format RuntimeMicrosoft Windows 2000Microsoft Windows XPMicrosoft Windows Server 2003+4 | 8/9/2009 | 16/6/2026 | Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf, (2) .wmv, or (3) .wma file, aka "Windows Media Header Parsing… | |
| Modificada | Alta (7.8) | 35% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 8/9/2009 | 16/6/2026 | Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size, and remain in the FIN-WAIT-1 or… | |
| Modificada | Alta (10) | 27% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista | 8/9/2009 | 16/6/2026 | The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby triggering misinterpretation of an unspecified field as a… | |
| Modificada | Alta (9.3) | 22% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 8/9/2009 | 16/6/2026 | The JScript scripting engine 5.1, 5.6, 5.7, and 5.8 in JScript.dll in Microsoft Windows, as used in Internet Explorer, does not properly load decoded scripts into memory before execution, which allows remote attackers to execute arbitrary code via a crafted web site that triggers memory corruption, aka "JScript Remote… | |
| Modificada | Alta (7.1) | 17% | 💥 Exploit | Microsoft Windows Server 2003 | 31/8/2009 | 16/6/2026 | win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different… | |
| Modificada | Crítica (9.8) | 42% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 12/8/2009 | 16/6/2026 | The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant,… | |
| Modificada | Media (6.9) | 1.3% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows VistaMicrosoft Windows XP | 12/8/2009 | 16/6/2026 | The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer… | |
| Modificada | Alta (9.3) | 30% | — | Microsoft Windows 2000Microsoft Windows ServerMicrosoft Windows Server 2003Microsoft Windows Server 2008+2 | 12/8/2009 | 16/6/2026 | Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow… | |
| Modificada | Media (4.6) | 5.9% | 💥 Exploit | Microsoft Windows Server 2003Microsoft Windows XP | 3/8/2009 | 16/6/2026 | The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the… | |
| Modificada | Alta (9.3) | 34% | — | Microsoft Internet ExplorerMicrosoft Windows Server 2003Microsoft Windows XPMicrosoft Windows Server 2008+2 | 29/7/2009 | 16/6/2026 | Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not properly handle attempts to access deleted objects in memory,… | |
| Modificada | Alta (9.3) | 26% | — | Microsoft DirectxMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP | 15/7/2009 | 16/6/2026 | The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does not properly validate unspecified size fields in QuickTime media files, which allows remote attackers to execute arbitrary code via a crafted… | |
| Modificada | Alta (9.3) | 27% | — | Microsoft DirectxMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP | 15/7/2009 | 16/6/2026 | The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly validating unspecified data values, which allows remote attackers to execute arbitrary code via a… | |
| Modificada | Alta (9.3) | 26% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 15/7/2009 | 16/6/2026 | Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "Embedded OpenType Font Integer Overflow Vulnerability." | |
| Modificada | Alta (8.8) | 37% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 15/7/2009 | 16/6/2026 | The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based… | |
| Modificada | Alta (7.2) | 1.4% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 10/6/2009 | 16/6/2026 | The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, aka "Windows Desktop Parameter Edit Vulnerability." | |
| Modificada | Alta (7.2) | 1.4% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 10/6/2009 | 16/6/2026 | The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability." |