Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
283 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 25% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP | 20/10/2003 | 16/6/2026 | The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information. | |
| Modificada | Alta (10) | 41% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP | 17/9/2003 | 16/6/2026 | Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715. | |
| Modificada | Alta (10) | 40% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP | 17/9/2003 | 16/6/2026 | Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and… | |
| Modificada | Media (5) | 7.7% | — | Microsoft Windows NT | 27/8/2003 | 16/6/2026 | The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the… | |
| Modificada | Alta (7.5) | 98% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NTMicrosoft Windows XP | 18/8/2003 | 16/6/2026 | Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms. | |
| Modificada | Alta (7.5) | 35% | — | Microsoft Windows 2000Microsoft Windows NTMicrosoft Windows XP | 18/8/2003 | 16/6/2026 | Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required. | |
| Modificada | Alta (7.5) | 45% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+3 | 7/8/2003 | 16/6/2026 | Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using a long "align" argument in an HR tag. | |
| Modificada | Media (5) | 34% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows NT | 9/6/2003 | 16/6/2026 | The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network… | |
| Modificada | Media (4.6) | 2.2% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows NTMicrosoft Windows XP | 12/5/2003 | 16/6/2026 | Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger. | |
| Modificada | Media (5) | 38% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows NTMicrosoft Windows XP | 2/4/2003 | 16/6/2026 | The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference. | |
| Modificada | Alta (7.5) | 24% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 98Microsoft Windows 98se+3 | 24/3/2003 | 16/6/2026 | Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack. | |
| Modificada | Alta (7.5) | 43% | 💥 Exploit | Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 2000Microsoft Windows NTMicrosoft Windows XP | 7/2/2003 | 16/6/2026 | Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information. | |
| Modificada | Baja (3.6) | 1.8% | — | Microsoft Windows 2000Microsoft Windows NTMicrosoft Windows XP | 31/12/2002 | 16/6/2026 | NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs. | |
| Modificada | Media (4.3) | 13% | 💥 Exploit | Microsoft Site ServerMicrosoft Site Server CommerceMicrosoft Windows NT | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp. | |
| Modificada | Baja (2.1) | 2.0% | — | Microsoft Windows 2000Microsoft Windows NTMicrosoft Windows XP | 31/12/2002 | 16/6/2026 | The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing. | |
| Modificada | Media (5) | 2.1% | — | Trend Micro Interscan Viruswall FOR Windows NT | 31/12/2002 | 16/6/2026 | Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message. | |
| Modificada | Media (5) | 26% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows NT | 31/12/2002 | 16/6/2026 | Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3. | |
| Modificada | Alta (7.5) | 16% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+4 | 23/12/2002 | 16/6/2026 | The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet. | |
| Modificada | Alta (10) | 15% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+4 | 23/12/2002 | 16/6/2026 | Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail. | |
| Modificada | Media (5) | 14% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+4 | 23/12/2002 | 16/6/2026 | Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability." | |
| Modificada | Media (5) | 15% | — | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 95Microsoft Windows 98+4 | 23/12/2002 | 16/6/2026 | Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error. | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows NT | 11/12/2002 | 16/6/2026 | Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862). | |
| Modificada | Media (4.6) | 2.8% | — | Microsoft Windows 2000Microsoft Windows NT | 12/11/2002 | 16/6/2026 | The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs. | |
| Modificada | Media (5) | 22% | — | Microsoft .net Windows ServerMicrosoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows NT+1 | 11/10/2002 | 16/6/2026 | Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol." | |
| Modificada | Alta (7.5) | 31% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 98Microsoft Windows 98se+3 | 10/10/2002 | 16/6/2026 | Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long… |