Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.43% | — | Trend Micro Scanmail Exchange | 22/8/2001 | 16/6/2026 | TrendMicro ScanMail for Exchange 3.5 Evaluation allows a local attacker to recover the administrative credentials for ScanMail via a combination of unprotected registry keys and weakly encrypted passwords. | |
| Modificada | Alta (7.5) | 6.4% | — | Microsoft Exchange Server | 21/7/2001 | 16/6/2026 | An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically. | |
| Modificada | Media (5) | 33% | — | Microsoft Exchange Server | 16/7/2001 | 16/6/2026 | Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite. | |
| Modificada | Media (5) | 37% | — | Microsoft Exchange ServerMicrosoft Internet Information Services | 2/6/2001 | 16/6/2026 | IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's. | |
| Modificada | Media (5) | 20% | — | Microsoft Exchange Server | 12/3/2001 | 16/6/2026 | Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands. | |
| Modificada | Alta (7.5) | 5.0% | — | Microsoft Exchange Server | 9/1/2001 | 16/6/2026 | The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Broadcom Inoculateit Agent FOR Exchange | 31/12/2000 | 23/9/2026 | Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the "From" field, which allows remote attackers to bypass virus protection. | |
| Modificada | Media (5) | 15% | — | Microsoft Exchange Server | 11/12/2000 | 16/6/2026 | Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability. | |
| Modificada | Media (5) | 15% | — | Microsoft Exchange ServerMicrosoft Outlook | 5/6/2000 | 16/6/2026 | Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From. | |
| Modificada | Media (5) | 5.1% | — | Microsoft Exchange ServerMicrosoft OutlookMicrosoft Windows Messaging | 29/2/2000 | 16/6/2026 | Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list. | |
| Modificada | Media (5) | 13% | — | Microsoft Exchange Server | 31/12/1999 | 16/6/2026 | Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error). | |
| Modificada | Alta (7.5) | 7.1% | — | Microsoft Exchange Server | 13/12/1999 | 16/6/2026 | Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed. | |
| Modificada | Media (5) | 26% | — | Microsoft Exchange Server | 6/8/1999 | 16/6/2026 | Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled. | |
| Modificada | Alta (10) | 18% | — | Microsoft Exchange Server | 1/12/1998 | 16/6/2026 | The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. | |
| Modificada | Media (4.6) | 1.5% | — | Broadcom Arcserve BackupBroadcom InoculanMicrosoft Exchange Server | 12/11/1998 | 16/6/2026 | The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext. | |
| Modificada | Media (5) | 7.6% | — | C2net Stonghold WEB ServerHP Open Market Secure WebserverMicrosoft Exchange ServerMicrosoft Internet Information Server+9 | 26/6/1998 | 16/6/2026 | Information from SSL-encrypted sessions via PKCS #1. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | IBM Lotus Domino Mail ServerMicrosoft Exchange Server | 1/1/1998 | 16/6/2026 | Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. |