Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

517 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)38%💥 ExploitBeosMicrosoft Windows 2000Microsoft Windows 95Microsoft Windows 98+219/5/200016/6/2026
Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.
ModificadaAlta (7.2)1.5%—Microsoft Windows 200011/5/200016/6/2026
The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data.
ModificadaMedia (5)5.7%—Microsoft Windows 200011/5/200016/6/2026
NTMail 5.x allows network users to bypass the NTMail proxy restrictions by redirecting their requests to NTMail's web configuration server.
ModificadaBaja (2.1)1.4%—Microsoft Windows 200020/4/200016/6/2026
The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability.
ModificadaMedia (5)7.5%—Microsoft Terminal ServerMicrosoft Windows 2000Microsoft Windows NT20/4/200016/6/2026
Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.
ModificadaCrítica (9.8)6.3%—Microsoft Windows 2000Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows NT+114/4/200016/6/2026
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
ModificadaAlta (7.2)1.7%—Microsoft Windows 20007/4/200016/6/2026
The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories.
ModificadaBaja (2.1)3.5%💥 ExploitMicrosoft Terminal ServerMicrosoft Windows 2000Microsoft Windows NT30/3/200016/6/2026
Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request.
ModificadaAlta (10)15%—Microsoft Windows 200015/2/200016/6/2026
The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs.
ModificadaBaja (2.1)2.5%—Microsoft Windows 2000Microsoft Windows NT20/1/200016/6/2026
A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.
ModificadaMedia (4.6)1.4%—Microsoft Windows 2000Microsoft Windows NT31/12/199916/6/2026
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.
ModificadaMedia (5)15%💥 ExploitMicrosoft Windows 2000Microsoft Windows NT1/12/199916/6/2026
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
ModificadaMedia (5)21%💥 ExploitMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows NT17/11/199916/6/2026
Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.
ModificadaAlta (7.5)10%💥 ExploitMicrosoft Windows 2000Microsoft Windows 95Microsoft Windows 98seSUN Solaris+111/8/199916/6/2026
DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
ModificadaMedia (6.2)2.9%💥 ExploitMicrosoft Windows 2000Microsoft Windows NT29/7/199916/6/2026
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
ModificadaAlta (7.8)8.5%—Microsoft Windows 2000Microsoft Windows NT20/7/199916/6/2026
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
ModificadaAlta (7.8)26%💥 ExploitMicrosoft Windows 2000Microsoft Windows 95Microsoft Windows 98Microsoft Windows NT3/7/199916/6/2026
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
ModificadaAlta (7.8)8.5%—Microsoft Windows 2000Microsoft Windows NT30/6/199916/6/2026
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
ModificadaAlta (7.1)7.3%—Microsoft Windows 2000Microsoft Windows NT23/6/199916/6/2026
The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.
ModificadaAlta (10)75%💥 ExploitMicrosoft Internet Information ServerMicrosoft Windows 2000Microsoft Windows NT16/6/199916/6/2026
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
ModificadaMedia (5)15%💥 ExploitMicrosoft Windows 2000Microsoft Windows NT27/5/199916/6/2026
Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.
ModificadaMedia (4.6)3.1%💥 ExploitMicrosoft Windows 2000Microsoft Windows NT20/5/199916/6/2026
Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.
ModificadaMedia (4.6)3.1%💥 ExploitMicrosoft Windows 2000Microsoft Windows NT17/5/199916/6/2026
Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.
ModificadaBaja (2.6)5.8%—Microsoft ExcelMicrosoft Windows 2000Microsoft Windows 95Microsoft Windows 98+17/5/199916/6/2026
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
ModificadaBaja (2.1)4.2%💥 ExploitMicrosoft Windows 2000Microsoft Windows NTMicrosoft Backoffice12/2/199916/6/2026
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.