Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

455 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+123/10/200816/6/2026
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October…
ModificadaAlta (7.1)32%💥 PoCBSDBsdi BSD OSCisco IOSDragonflybsd+1520/10/200816/6/2026
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as…
ModificadaAlta (10)39%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+115/10/200816/6/2026
Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a crafted length, aka "SMB Buffer Underflow Vulnerability."
ModificadaAlta (8.4)1.5%—Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP15/10/200816/6/2026
Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to validation of parameters for Virtual Address Descriptors…
ModificadaAlta (7.2)1.9%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+115/10/200816/6/2026
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."
ModificadaAlta (7.2)1.5%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows XP15/10/200816/6/2026
Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows Kernel Unhandled Exception Vulnerability."…
ModificadaAlta (7.2)1.6%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+115/10/200816/6/2026
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain privileges via a crafted application, aka…
ModificadaAlta (7.1)49%💥 ExploitMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+116/9/200816/6/2026
srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with…
ModificadaAlta (9.4)34%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows XP8/7/200816/6/2026
Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting "records from a response that is outside the remote server's authority," aka "DNS Cache Poisoning Vulnerability,"…
ModificadaMedia (5.4)20%—Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP12/6/200816/6/2026
Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "PGM Malformed Fragment Vulnerability."
ModificadaAlta (7.1)23%—Microsoft Windows Server 2003Microsoft Windows XP12/6/200816/6/2026
Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."
ModificadaAlta (9.3)30%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XPMicrosoft Windows Vista23/4/200816/6/2026
Buffer overflow in the Microsoft HeartbeatCtl ActiveX control in HRTBEAT.OCX allows remote attackers to execute arbitrary code via the Host argument to an unspecified method.
ModificadaAlta (9)37%💥 ExploitMicrosoft Windows-ntMicrosoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+121/4/200816/6/2026
Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has…
ModificadaAlta (7.5)32%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows VistaMicrosoft Windows XP8/4/200816/6/2026
The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.
ModificadaAlta (7.1)32%—Microsoft Home ServerMicrosoft Small Business ServerMicrosoft Windows 2000Microsoft Windows 2003 Server+28/1/200816/6/2026
The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."
ModificadaMedia (6.4)52%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 200314/11/200716/6/2026
The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.
ModificadaAlta (7.1)23%💥 ExploitMicrosoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows VistaMicrosoft Windows XP+127/9/200716/6/2026
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file with a large tEXt chunk that possibly triggers an integer overflow in PNG chunk size handling, as demonstrated by badlycrafted.png.
ModificadaAlta (9.3)52%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows XP14/8/200716/6/2026
Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow.
ModificadaMedia (5.1)30%—Microsoft Windows Server 2003Microsoft Windows XP10/10/200616/6/2026
Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed…
ModificadaAlta (10)29%💥 ExploitMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP13/6/200616/6/2026
The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory,…
ModificadaAlta (9.3)38%💥 ExploitMicrosoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2000 Advanced ServerMicrosoft Windows 2003 Server+314/2/200616/6/2026
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.
ModificadaAlta (7.5)44%—Microsoft Exchange ServerMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP13/10/200516/6/2026
Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.
ModificadaAlta (10)30%—Microsoft Exchange ServerMicrosoft Windows Server 2003Microsoft Windows XP3/11/200416/6/2026
The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length…
ModificadaAlta (10)64%💥 ExploitMicrosoft Exchange ServerMicrosoft Windows 2000Microsoft Windows NTMicrosoft Windows Server 20033/11/200416/6/2026
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer,"…
AnalizadaMedia (5)80%💥 ExploitJuniper JunosMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows 98se+818/8/200416/6/2026
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
Orbitaley — Vulnerabilidades