Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 350 respecto a la semana anterior
Críticas / altas1260▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 48% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 21/10/2005 | 16/6/2026 | Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different… | |
| Modificada | Media (6.5) | 62% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows XP | 13/10/2005 | 16/6/2026 | Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW… | |
| Modificada | Alta (7.5) | 44% | — | Microsoft Exchange ServerMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP | 13/10/2005 | 16/6/2026 | Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string. | |
| Modificada | Alta (7.5) | 37% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 13/10/2005 | 16/6/2026 | The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages. | |
| Modificada | Media (5) | 36% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 12/10/2005 | 16/6/2026 | The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function,… | |
| Modificada | Alta (7.5) | 53% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 12/10/2005 | 16/6/2026 | COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code. | |
| Modificada | Media (5) | 33% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 12/10/2005 | 16/6/2026 | Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality. | |
| Modificada | Media (5) | 33% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 12/10/2005 | 16/6/2026 | Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability." | |
| Modificada | Media (4.6) | 1.4% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 6/10/2005 | 16/6/2026 | CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not satisfy certain NTFS conventions, which could cause ACLs… | |
| Modificada | Baja (2.1) | 1.2% | — | Microsoft Windows 2003 ServerMicrosoft Windows XP | 1/9/2005 | 16/6/2026 | The user interface in the Windows Firewall does not properly display certain malformed entries in the Windows Registry, which makes it easier for attackers with administrator privileges to hide activities if the administrator only uses the Windows Firewall interface to monitor exceptions. NOTE: the vendor disputes… | |
| Modificada | Alta (7.5) | 46% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+2 | 10/8/2005 | 16/6/2026 | Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to elevate privileges or execute arbitrary code via a crafted message. | |
| Modificada | Alta (7.5) | 55% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 10/8/2005 | 16/6/2026 | Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message. | |
| Modificada | Baja (3.6) | 1.7% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 10/8/2005 | 16/6/2026 | Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used. | |
| Modificada | Media (5) | 57% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 10/8/2005 | 16/6/2026 | The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests. | |
| Modificada | Alta (10) | 93% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows XP | 10/8/2005 | 16/6/2026 | Desbordamiento de búfer basado en pila en el servicio Plug and Play (PnP) de Microsoft Windows 2000 y Windows XP Service Pack 1 ; permite a atacantes remotos ejecutar código de su elección a través de un paquete manipulado. También los usuarios locales pueden aumentar sus privilegios a través de aplicaciones… | |
| Modificada | Alta (7.2) | 1.8% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 95Microsoft Windows 98+3 | 27/7/2005 | 16/6/2026 | Desbordamiento de búfer en cierto driver USB, usado en Windows, permite que atacantes ejecuten código arbitrario. | |
| Modificada | Media (5) | 26% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows XP | 19/7/2005 | 16/6/2026 | netman.dll en Microsoft Windows Connections Manager Library permite que usuarios locales causen una denegación de servicio (caída de Network Connectios Service) mediante un argumento grande a una cierta función, también conocido como "Vulnerabilidad de Administración de conexión de red". | |
| Modificada | Alta (10) | 47% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows XP | 14/6/2005 | 16/6/2026 | Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer. | |
| Modificada | Media (5.1) | 13% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 2003 ServerMicrosoft Windows 98+3 | 14/6/2005 | 16/6/2026 | Microsoft Agent permite a los atacantes remotos falsificar contenido de Internet de confianza y ejecutar código arbitrario disfrazando las indicaciones de seguridad en una página web maliciosa. | |
| Modificada | Alta (7.2) | 7.3% | — | Microsoft Windows 2003 ServerMicrosoft Windows XP | 14/6/2005 | 16/6/2026 | Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters. | |
| Modificada | Alta (7.5) | 59% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 14/6/2005 | 16/6/2026 | Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability." | |
| Modificada | Alta (7.5) | 25% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 2003 ServerMicrosoft Windows 98+3 | 14/6/2005 | 16/6/2026 | El desbordamiento de búfer en Microsoft Step-by-Step Interactive Training (orun32.exe) permite a los atacantes remotos ejecutar código arbitrario a través de un archivo de enlace de marcadores (extensión.cbo, cbl o.cbm) con un campo de usuario largo. | |
| Modificada | Alta (7.5) | 27% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP | 13/6/2005 | 16/6/2026 | Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the function to overwrite previously freed memory, as demonstrated using a… | |
| Modificada | Media (5) | 6.9% | — | Microsoft Windows XP | 1/6/2005 | 16/6/2026 | Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can be cleared from the RPC cache. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. |