Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
517 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 7.4% | — | Microsoft OfficeMicrosoft Windows 2000Microsoft Windows MEMicrosoft Windows NT | 12/2/2001 | 16/6/2026 | Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability. | |
| Modificada | Media (5) | 13% | — | Microsoft Windows 2000 | 12/2/2001 | 16/6/2026 | Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability. | |
| Modificada | Alta (10) | 75% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows NT | 9/1/2001 | 16/6/2026 | Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability. | |
| Modificada | Media (5) | 13% | — | Microsoft Windows 2000 | 9/1/2001 | 16/6/2026 | Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input. | |
| Modificada | Media (5) | 13% | — | Microsoft Windows 2000Microsoft Windows NT | 31/12/2000 | 23/9/2026 | Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back. | |
| Modificada | Alta (7.5) | 13% | — | Microsoft Systems Management ServerMicrosoft Windows 2000Microsoft Windows NT | 19/12/2000 | 23/9/2026 | Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this… | |
| Modificada | Media (4.6) | 2.2% | — | Microsoft Windows 2000 | 19/12/2000 | 23/9/2026 | The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability. | |
| Modificada | Alta (10) | 27% | — | Microsoft Windows 2000 | 11/12/2000 | 23/9/2026 | Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability. | |
| Modificada | Media (4.6) | 1.7% | — | Microsoft Windows 2000 | 21/11/2000 | 16/6/2026 | Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout"… | |
| Modificada | Media (4.6) | 7.6% | 💥 Exploit | Microsoft Windows 2000 | 14/11/2000 | 16/6/2026 | Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the "Still Image Service Privilege Escalation" vulnerability. | |
| Modificada | Alta (7.5) | 40% | 💥 Exploit | Microsoft Windows 2000 | 14/11/2000 | 16/6/2026 | The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability. | |
| Modificada | Media (4.6) | 1.4% | — | Microsoft Windows 2000Microsoft Windows 98Microsoft Windows 98se | 20/10/2000 | 16/6/2026 | The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option for the first file that is listed in the… | |
| Modificada | Baja (2.1) | 1.5% | — | Microsoft Windows 2000 | 20/10/2000 | 16/6/2026 | Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability. | |
| Modificada | Media (4.6) | 4.4% | 💥 Exploit | Microsoft Windows 2000 | 20/10/2000 | 16/6/2026 | The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability. | |
| Modificada | Alta (7.5) | 16% | — | Microsoft Windows 2000Microsoft Windows 95Microsoft Windows 98Microsoft Windows NT | 29/8/2000 | 16/6/2026 | Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram. | |
| Modificada | Media (5) | 33% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows NT | 27/7/2000 | 16/6/2026 | The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability. | |
| Modificada | Media (4.6) | 1.9% | — | Microsoft Windows 2000Microsoft Windows NT | 25/7/2000 | 16/6/2026 | The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative Shell Path" vulnerability. | |
| Modificada | Baja (2.1) | 2.5% | — | Microsoft Windows 2000Microsoft Windows NT | 1/7/2000 | 16/6/2026 | A Windows NT administrator account has the default name of Administrator. | |
| Modificada | Media (5) | 16% | 💥 Exploit | Microsoft Windows 2000 | 30/6/2000 | 16/6/2026 | Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization. | |
| Modificada | Media (5) | 22% | 💥 Exploit | Microsoft Windows 2000 | 30/6/2000 | 16/6/2026 | Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash. | |
| Modificada | Media (4.6) | 1.9% | — | Microsoft Windows 2000 | 15/6/2000 | 16/6/2026 | Windows 2000 allows a local user process to access another user's desktop within the same windows station, aka the "Desktop Separation" vulnerability. | |
| Modificada | Media (5) | 18% | — | Microsoft Windows 2000Microsoft Windows NT | 5/6/2000 | 16/6/2026 | Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length. | |
| Modificada | Alta (10) | 6.0% | — | Apple MacosLinux KernelMicrosoft Windows 2000Microsoft Windows 95+2 | 1/6/2000 | 16/6/2026 | A system does not present an appropriate legal message or warning to a user who is accessing it. | |
| Modificada | Baja (3.6) | 2.5% | — | Microsoft Windows 2000 | 1/6/2000 | 16/6/2026 | The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability. | |
| Modificada | Media (5) | 18% | — | Microsoft Terminal ServerMicrosoft Windows 2000Microsoft Windows 95Microsoft Windows 98+1 | 25/5/2000 | 16/6/2026 | The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability. |