Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

283 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)2.3%—Microsoft Windows 2000Microsoft Windows NT18/6/200116/6/2026
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.
ModificadaAlta (7.2)4.8%—Microsoft Windows NT3/5/200116/6/2026
Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.
ModificadaAlta (7.2)2.1%—Microsoft Windows NT12/3/200116/6/2026
NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access.
ModificadaMedia (5)17%—Microsoft Windows NT12/3/200116/6/2026
Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability.
ModificadaAlta (10)8.4%—Microsoft Windows NT16/2/200116/6/2026
The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.
ModificadaAlta (7.5)5.6%—Microsoft Windows NT16/2/200116/6/2026
The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities.
ModificadaMedia (4.6)5.0%—Microsoft Windows 2000Microsoft Windows NT16/2/200116/6/2026
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.
ModificadaAlta (7.1)3.0%💥 ExploitMicrosoft Windows NT12/2/200116/6/2026
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.
ModificadaMedia (5)7.4%—Microsoft OfficeMicrosoft Windows 2000Microsoft Windows MEMicrosoft Windows NT12/2/200116/6/2026
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
ModificadaAlta (10)75%💥 ExploitMicrosoft Windows 2000Microsoft Windows NT9/1/200116/6/2026
Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.
ModificadaMedia (5)46%—Microsoft Windows 95Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows ME+19/1/200116/6/2026
Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities. NOTE: this candidate…
ModificadaAlta (7.5)16%—Microsoft Windows NT9/1/200116/6/2026
Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the "Terminal Server Login Buffer Overflow" vulnerability.
ModificadaMedia (5)13%—Microsoft Windows 2000Microsoft Windows NT31/12/200023/9/2026
Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.
ModificadaAlta (7.5)13%—Microsoft Systems Management ServerMicrosoft Windows 2000Microsoft Windows NT19/12/200023/9/2026
Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this…
ModificadaMedia (5)22%—Microsoft Windows NT14/12/200023/9/2026
The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on the target machine.
ModificadaMedia (5)19%—Microsoft Internet Information ServerMicrosoft Windows NT14/11/200016/6/2026
Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability.
ModificadaAlta (7.5)16%—Microsoft Windows 2000Microsoft Windows 95Microsoft Windows 98Microsoft Windows NT29/8/200016/6/2026
Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.
ModificadaMedia (5)33%💥 ExploitMicrosoft Windows 2000Microsoft Windows NT27/7/200016/6/2026
The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability.
ModificadaMedia (4.6)1.9%—Microsoft Windows 2000Microsoft Windows NT25/7/200016/6/2026
The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative Shell Path" vulnerability.
ModificadaBaja (2.1)2.5%—Microsoft Windows 2000Microsoft Windows NT1/7/200016/6/2026
A Windows NT administrator account has the default name of Administrator.
ModificadaMedia (5)19%💥 ExploitMicrosoft Windows NT8/6/200016/6/2026
The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability.
ModificadaMedia (5)18%—Microsoft Windows 2000Microsoft Windows NT5/6/200016/6/2026
Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.
ModificadaAlta (10)6.0%—Apple MacosLinux KernelMicrosoft Windows 2000Microsoft Windows 95+21/6/200016/6/2026
A system does not present an appropriate legal message or warning to a user who is accessing it.
ModificadaMedia (5)18%—Microsoft Terminal ServerMicrosoft Windows 2000Microsoft Windows 95Microsoft Windows 98+125/5/200016/6/2026
The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability.
ModificadaMedia (5)18%—Microsoft Windows NT25/5/200016/6/2026
The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the "HostAnnouncement Flooding" or "HostAnnouncement Frame" vulnerability.