Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

94 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)32%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+310/1/200516/6/2026
Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than…
ModificadaAlta (10)31%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+310/1/200516/6/2026
Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.
ModificadaMedia (5)59%💥 ExploitNortel IP Softphone 2050Nortel Media Communication Server 5100Nortel Media Communication Server 5200Nortel Media Processing Server+1523/12/200416/6/2026
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number…
ModificadaMedia (5)27%—Nortel IP Softphone 2050Nortel Mobile Voice Client 2050Nortel Optivity Telephony ManagerMicrosoft Windows 2000+515/12/200416/6/2026
The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by…
ModificadaAlta (10)82%💥 ExploitGreg Roelofs LibpngMicrosoft MSN MessengerMicrosoft Windows Media PlayerMicrosoft Windows Messenger+223/11/200416/6/2026
Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3)…
ModificadaAlta (7.5)75%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows NT+13/11/200416/6/2026
Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer…
ModificadaBaja (2.1)1.8%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows NT+13/11/200416/6/2026
"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the…
ModificadaAlta (10)47%💥 ExploitMicrosoft Internet ExplorerMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows ME+13/11/200416/6/2026
Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
ModificadaMedia (5)34%—Avaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+1418/8/200416/6/2026
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by…
AnalizadaMedia (5)80%💥 ExploitJuniper JunosMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows 98se+818/8/200416/6/2026
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
ModificadaMedia (5)26%—Microsoft DirectxMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98+36/8/200416/6/2026
IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
ModificadaAlta (10)45%—Avaya Ip600 Media ServersAvaya Definity ONE Media ServerAvaya S8100Avaya Modular Messaging Message Storage Server+76/8/200416/6/2026
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
ModificadaAlta (7.8)27%—Microsoft Internet ExplorerMicrosoft OutlookMicrosoft Windows 98Microsoft Windows 98se+427/7/200416/6/2026
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.
ModificadaAlta (7.5)81%💥 ExploitMicrosoft NetmeetingMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98+31/6/200416/6/2026
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake…
ModificadaAlta (7.5)30%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+31/6/200416/6/2026
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
ModificadaAlta (7.5)27%—Microsoft NetmeetingMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98+21/6/200416/6/2026
Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.
ModificadaAlta (7.5)85%💥 ExploitMicrosoft NetmeetingMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98+31/6/200416/6/2026
Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a…
ModificadaMedia (5.1)17%—Microsoft Windows 2000Microsoft Windows 98Microsoft Windows NTMicrosoft Windows Server 2003+117/11/200316/6/2026
A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability…
ModificadaAlta (7.5)45%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+37/8/200316/6/2026
Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using a long "align" argument in an HR tag.
ModificadaAlta (7.5)24%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 98Microsoft Windows 98se+324/3/200316/6/2026
Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.
ModificadaMedia (4.9)2.5%—SGI IrixDebian LinuxMandrakesoft Mandrake LinuxMicrosoft Windows 98+731/12/200216/6/2026
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
ModificadaMedia (5)15%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+423/12/200216/6/2026
Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.
ModificadaAlta (10)15%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+423/12/200216/6/2026
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.
ModificadaMedia (5)14%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+423/12/200216/6/2026
Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."
ModificadaAlta (7.5)16%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+423/12/200216/6/2026
The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet.
Orbitaley — Vulnerabilidades