Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 37% | 💥 Exploit | Microsoft Windows XP | 14/1/2009 | 16/6/2026 | Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file. | |
| Modificada | Crítica (9.8) | 45% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 14/1/2009 | 16/6/2026 | SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the… | |
| Modificada | Alta (10) | 46% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 14/1/2009 | 16/6/2026 | Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans request, aka "SMB Buffer Overflow Remote Code Execution… | |
| Modificada | Crítica (9.8) | 14% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows Server 2008+2 | 10/12/2008 | 16/6/2026 | Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be… | |
| Modificada | Alta (9.3) | 31% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows Server 2008+2 | 10/12/2008 | 16/6/2026 | Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WMF file, which triggers a buffer overflow, aka "GDI Integer Overflow Vulnerability." | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 23/10/2008 | 16/6/2026 | The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October… | |
| Modificada | Alta (7.1) | 32% | 💥 PoC | BSDBsdi BSD OSCisco IOSDragonflybsd+15 | 20/10/2008 | 16/6/2026 | The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as… | |
| Modificada | Alta (10) | 39% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 15/10/2008 | 16/6/2026 | Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a crafted length, aka "SMB Buffer Underflow Vulnerability." | |
| Modificada | Alta (8.4) | 1.5% | — | Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP | 15/10/2008 | 16/6/2026 | Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to validation of parameters for Virtual Address Descriptors… | |
| Modificada | Alta (7.2) | 4.0% | 💥 Exploit | Microsoft Windows 2003 ServerMicrosoft Windows XP | 15/10/2008 | 16/6/2026 | afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths… | |
| Modificada | Alta (7.2) | 1.9% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 15/10/2008 | 16/6/2026 | The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability." | |
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows XP | 15/10/2008 | 16/6/2026 | Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows Kernel Unhandled Exception Vulnerability."… | |
| Modificada | Alta (7.2) | 1.6% | — | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 15/10/2008 | 16/6/2026 | The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain privileges via a crafted application, aka… | |
| Modificada | Media (4.3) | 16% | 💥 Exploit | Microsoft Windows XP | 30/9/2008 | 16/6/2026 | gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a certain crash.ico file on a web site, and allows user-assisted attackers to cause a denial of service… | |
| Modificada | Media (4.3) | 8.6% | 💥 Exploit | Microsoft Windows XP | 29/9/2008 | 16/6/2026 | Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application crash) via a crafted .ZIP file. | |
| Modificada | Alta (7.1) | 49% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+1 | 16/9/2008 | 16/6/2026 | srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with… | |
| Modificada | Alta (9.3) | 37% | — | Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+10 | 11/9/2008 | 16/6/2026 | Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006,… | |
| Modificada | Alta (9.3) | 52% | 💥 Exploit | Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+9 | 11/9/2008 | 16/6/2026 | gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000… | |
| Modificada | Alta (9.3) | 31% | — | Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+12 | 11/9/2008 | 16/6/2026 | gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000… | |
| Modificada | Alta (9.3) | 55% | 💥 Exploit | Microsoft Windows Media EncoderMicrosoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2003 Server+1 | 11/9/2008 | 16/6/2026 | Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers to execute arbitrary code via a long first argument to the GetDetailsString method, aka "Windows Media Encoder Buffer Overrun Vulnerability." | |
| Modificada | Alta (9.3) | 53% | 💥 Exploit | Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+12 | 11/9/2008 | 16/6/2026 | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000… | |
| Modificada | Alta (9) | 28% | — | Microsoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Vista+1 | 13/8/2008 | 16/6/2026 | Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that is used to access an array of function pointers. | |
| Modificada | Alta (9) | 36% | — | Microsoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Vista+1 | 13/8/2008 | 16/6/2026 | The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted event subscription request. | |
| Modificada | Alta (9.3) | 46% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 13/8/2008 | 16/6/2026 | Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted… | |
| Modificada | Alta (9.3) | 22% | — | Microsoft Windows XP | 12/8/2008 | 16/6/2026 | nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008. |