Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

517 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)39%—Microsoft Windows 200010/6/200916/6/2026
The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active…
ModificadaAlta (10)32%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows ServerMicrosoft Windows Server 2008+210/6/200916/6/2026
The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect…
ModificadaAlta (9)35%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows ServerMicrosoft Windows Server 2008+210/6/200916/6/2026
The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library…
ModificadaMedia (4.9)3.9%💥 PoCMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows Vista+110/6/200916/6/2026
The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."
ModificadaAlta (10)21%—Microsoft Windows 200010/6/200916/6/2026
Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in…
AnalizadaAlta (8.8)51%⚠ Explotación activaMicrosoft DirectxMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2003+129/5/200916/6/2026
Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May…
ModificadaAlta (9.3)12%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+315/4/200916/6/2026
Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008; and WinINet in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1,…
ModificadaAlta (9.3)34%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP15/4/200916/6/2026
Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an…
ModificadaMedia (5.8)5.1%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+115/4/200916/6/2026
Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own…
ModificadaAlta (9.3)28%—Microsoft Office Converter PackMicrosoft Office WordMicrosoft Windows 2000Microsoft Windows Server 2003+115/4/200916/6/2026
The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter…
ModificadaAlta (9.3)26%—Microsoft Office WordMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP15/4/200916/6/2026
Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and the Word 6 text converter in Microsoft Office Word 2000 SP3 and 2002 SP3; allows remote attackers to execute arbitrary code via a crafted Word 6 file that contains malformed…
ModificadaAlta (10)14%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+115/4/200916/6/2026
Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services…
ModificadaMedia (6.4)34%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 200811/3/200916/6/2026
The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that…
ModificadaMedia (5.8)27%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 200811/3/200916/6/2026
The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and…
ModificadaMedia (5.5)23%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 200811/3/200916/6/2026
The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and…
ModificadaBaja (3.5)17%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 200811/3/200916/6/2026
Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by…
ModificadaAlta (7.1)15%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+110/3/200916/6/2026
The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not properly validate the client's key exchange data in Transport Layer Security (TLS) handshake…
ModificadaAlta (7.2)1.5%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+110/3/200916/6/2026
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer Vulnerability."
ModificadaAlta (7.8)1.4%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+110/3/200916/6/2026
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability."
ModificadaAlta (9.3)32%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+110/3/200916/6/2026
The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote attackers to execute arbitrary code via a crafted (1) Windows…
ModificadaAlta (7.2)6.3%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+121/1/200916/6/2026
Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media, (3) connecting a USB device, and (4) connecting a Firewire device; (5) allows user-assisted…
ModificadaAlta (7.6)18%—Microsoft Windows 2000Microsoft Windows 95Microsoft Windows 9815/1/200916/6/2026
Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server. NOTE: this problem may be limited when Windows 95/98 clients are used, or if the…
ModificadaCrítica (9.8)45%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+114/1/200916/6/2026
SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the…
ModificadaAlta (10)46%—Microsoft Windows 2000Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista+114/1/200916/6/2026
Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans request, aka "SMB Buffer Overflow Remote Code Execution…
ModificadaCrítica (9.8)14%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows Server 2008+210/12/200816/6/2026
Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be…