Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 38% | 💥 Exploit | BeosMicrosoft Windows 2000Microsoft Windows 95Microsoft Windows 98+2 | 19/5/2000 | 16/6/2026 | Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability. | |
| Modificada | Media (5) | 18% | 💥 Exploit | Microsoft Windows 95Microsoft Windows 98 | 2/5/2000 | 16/6/2026 | Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name. | |
| Modificada | Crítica (9.8) | 6.3% | — | Microsoft Windows 2000Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows NT+1 | 14/4/2000 | 16/6/2026 | The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache. | |
| Modificada | Media (5) | 20% | 💥 Exploit | Microsoft Windows 95Microsoft Windows 98Microsoft Windows 98se | 4/3/2000 | 16/6/2026 | Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability. | |
| Modificada | Alta (7.2) | 3.9% | 💥 Exploit | Microsoft Windows 95Microsoft Windows 98Microsoft Windows NT | 18/2/2000 | 16/6/2026 | Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive. | |
| Modificada | Baja (2.1) | 3.8% | 💥 Exploit | Microsoft Windows 95Microsoft Windows 98Microsoft Windows NT | 4/2/2000 | 16/6/2026 | Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file. | |
| Modificada | Media (4.6) | 2.7% | 💥 Exploit | Microsoft Windows 95Microsoft Windows 98Microsoft Windows NT | 10/12/1999 | 16/6/2026 | The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed. | |
| Modificada | Alta (7.8) | 7.9% | — | Microsoft Windows 95Microsoft Windows 98 | 29/11/1999 | 16/6/2026 | A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords. | |
| Modificada | Media (5) | 21% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 98Microsoft Windows NT | 17/11/1999 | 16/6/2026 | Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word. | |
| Modificada | Alta (7.6) | 15% | 💥 Exploit | Microsoft Windows 95Microsoft Windows 98 | 12/11/1999 | 16/6/2026 | The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability. | |
| Modificada | Alta (7.5) | 12% | — | Microsoft Terminal ServerMicrosoft Windows 95Microsoft Windows 98seMicrosoft Windows NT | 20/9/1999 | 16/6/2026 | Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability. | |
| Modificada | Baja (2.6) | 8.0% | 💥 Exploit | Microsoft Windows 95Microsoft Windows 98 | 16/8/1999 | 16/6/2026 | Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 95Microsoft Windows 98seSUN Solaris+1 | 11/8/1999 | 16/6/2026 | DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes. | |
| Modificada | Alta (7.8) | 26% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 95Microsoft Windows 98Microsoft Windows NT | 3/7/1999 | 16/6/2026 | Denial of service in various Windows systems via malformed, fragmented IGMP packets. | |
| Modificada | Baja (2.6) | 5.8% | — | Microsoft ExcelMicrosoft Windows 2000Microsoft Windows 95Microsoft Windows 98+1 | 7/5/1999 | 16/6/2026 | A remote attacker can disable the virus warning mechanism in Microsoft Excel 97. | |
| Modificada | Media (5) | 17% | — | Microsoft Windows 95Microsoft Windows 98Microsoft Windows NT | 12/4/1999 | 16/6/2026 | Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files. | |
| Modificada | Media (5) | 13% | — | Microsoft Windows 95Microsoft Windows 98Microsoft Windows NT | 8/3/1999 | 16/6/2026 | Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables. | |
| Modificada | Media (5) | 14% | — | Microsoft Windows 95Microsoft Windows 98 | 6/2/1999 | 16/6/2026 | Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing. | |
| Modificada | Media (5) | 17% | — | Microsoft Windows 98 | 25/1/1999 | 16/6/2026 | Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets. |