Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
517 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 4.9% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 2000Microsoft Windows NT | 25/6/2002 | 16/6/2026 | smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit. | |
| Modificada | Media (5) | 47% | 💥 Exploit | Microsoft Windows 2000 | 18/6/2002 | 16/6/2026 | LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445. | |
| Modificada | Media (5) | 27% | — | Microsoft Internet Information ServicesMicrosoft SQL ServerMicrosoft Windows 2000 | 16/5/2002 | 16/6/2026 | The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input. | |
| Modificada | Alta (7.8) | 0.78% | — | Microsoft Windows 2000 | 4/4/2002 | 16/6/2026 | Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access. | |
| Modificada | Alta (7.2) | 3.3% | — | Microsoft Windows 2000Microsoft Windows NTMicrosoft Windows XP | 4/4/2002 | 16/6/2026 | Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request. | |
| Modificada | Alta (7.6) | 18% | — | Microsoft Windows 2000Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows NT | 15/3/2002 | 16/6/2026 | Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled. | |
| Modificada | Media (5) | 35% | — | Microsoft Exchange ServerMicrosoft Windows 2000Microsoft Windows XP | 8/3/2002 | 16/6/2026 | SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request. | |
| Modificada | Alta (7.5) | 17% | — | Microsoft InterixMicrosoft Windows 2000 | 8/3/2002 | 16/6/2026 | Buffer overflow in telnet server in Windows 2000 and Interix 2.2 allows remote attackers to execute arbitrary code via malformed protocol options. | |
| Modificada | Alta (10) | 16% | — | Microsoft Windows 2000Microsoft Windows NT | 8/3/2002 | 16/6/2026 | In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from… | |
| Modificada | Alta (7.5) | 35% | — | Microsoft Windows 2000Microsoft Windows 95Microsoft Windows 98Microsoft Windows 98se+2 | 8/3/2002 | 16/6/2026 | Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. NOTE: this candidate may be split or merged with other candidates. This and other PROTOS-related… | |
| Modificada | Alta (7.5) | 22% | — | Microsoft Exchange ServerMicrosoft Windows 2000 | 8/3/2002 | 16/6/2026 | SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials. | |
| Modificada | Baja (2.1) | 2.1% | — | Microsoft Windows 2000 | 31/12/2001 | 16/6/2026 | RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command. NOTE: the vendor disputes this issue, saying that administrative… | |
| Modificada | Baja (2.1) | 3.5% | 💥 Exploit | Microsoft Windows 2000 | 31/12/2001 | 16/6/2026 | RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. NOTE: the vendor disputes this vulnerability, however the vendor also… | |
| Modificada | Baja (3.6) | 3.5% | 💥 Exploit | Microsoft Windows 2000 | 31/12/2001 | 16/6/2026 | RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it | |
| Modificada | Alta (7.5) | 4.0% | — | Microsoft Windows 2000 | 31/12/2001 | 16/6/2026 | Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended. | |
| Modificada | Baja (2.1) | 3.1% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows XP | 31/12/2001 | 16/6/2026 | Win32k.sys (aka Graphics Device Interface (GDI)) in Windows 2000 and XP allows local users to cause a denial of service (system crash) by calling the ShowWindow function after receiving a WM_NCCREATE message. | |
| Modificada | Media (5) | 7.4% | — | Microsoft SQL ServerMicrosoft Windows 2000Microsoft Windows NTMicrosoft Windows XP | 20/12/2001 | 16/6/2026 | Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service. | |
| Modificada | Media (5) | 27% | 💥 Exploit | Microsoft Windows 2000 | 7/12/2001 | 16/6/2026 | Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (IKE) UDP port 500 with packets that contain a large number of dot characters. | |
| Modificada | Media (5) | 32% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows NT | 6/12/2001 | 16/6/2026 | Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets. | |
| Modificada | Alta (7.5) | 4.8% | — | Microsoft Windows 2000Microsoft Windows XP | 6/12/2001 | 16/6/2026 | Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Address Translation (NAT). | |
| Modificada | Media (5) | 8.0% | — | Microsoft Windows 2000 | 20/9/2001 | 16/6/2026 | Buffer overflow in IrDA driver providing infrared data exchange on Windows 2000 allows attackers who are physically close to the machine to cause a denial of service (reboot) via a malformed IrDA packet. | |
| Modificada | Media (5) | 17% | — | Microsoft Exchange ServerMicrosoft SQL ServerMicrosoft Windows NTMicrosoft Windows 2000 | 20/9/2001 | 16/6/2026 | Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs. | |
| Modificada | Media (5) | 19% | — | Microsoft Exchange ServerMicrosoft Windows 2000Microsoft Windows NT | 20/9/2001 | 16/6/2026 | Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed posts. | |
| Modificada | Alta (7.5) | 9.4% | — | Microsoft Windows 2000Microsoft Windows NT | 31/8/2001 | 16/6/2026 | By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses. | |
| Modificada | Alta (7.5) | 21% | — | Microsoft Windows 2000 | 14/8/2001 | 16/6/2026 | Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activities such as mail relaying. |