Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.1)22%💥 ExploitMicrosoft Windows Media Player12/3/200116/6/2026
Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file named skin.wmz, then referencing that skin in the codebase parameter to an applet tag, aka the Windows Media Player Skins File Download" vulnerability.
ModificadaMedia (5)17%—Microsoft Windows Media Services12/2/200116/6/2026
Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the "Severed Windows Media Server Connection" vulnerability.
ModificadaMedia (5)7.4%—Microsoft OfficeMicrosoft Windows 2000Microsoft Windows MEMicrosoft Windows NT12/2/200116/6/2026
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
ModificadaAlta (7.5)19%💥 ExploitMicrosoft Windows Media Player9/1/200116/6/2026
Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the ".ASX Buffer Overrun" vulnerability.
ModificadaMedia (5)46%—Microsoft Windows 95Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows ME+19/1/200116/6/2026
Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities. NOTE: this candidate…
ModificadaMedia (4.6)14%💥 ExploitMicrosoft Windows Media Player9/1/200116/6/2026
Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.
ModificadaMedia (5)14%💥 ExploitMicrosoft Windows Media Player19/12/200023/9/2026
Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.
ModificadaMedia (5)13%—Microsoft Windows 95Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows ME19/12/200023/9/2026
NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network.
ModificadaMedia (6.4)75%💥 ExploitMicrosoft Windows 95Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows ME19/12/200023/9/2026
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.
ModificadaBaja (2.6)15%—Microsoft Windows Media Services14/11/200016/6/2026
Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.
ModificadaMedia (5)32%💥 ExploitMicrosoft Windows Media Services30/5/200016/6/2026
Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder Request" vulnerability.
ModificadaMedia (5)14%—Microsoft Windows Media Rights Manager17/3/200016/6/2026
Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the "Malformed Media License Request" Vulnerability.
ModificadaMedia (5)5.1%—Microsoft Exchange ServerMicrosoft OutlookMicrosoft Windows Messaging29/2/200016/6/2026
Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.
ModificadaMedia (5)21%💥 ExploitMicrosoft Windows Media Services23/2/200016/6/2026
The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerability.