Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

283 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)1.5%—Microsoft Windows NT31/12/199916/6/2026
Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.
ModificadaAlta (7.5)18%—Microsoft Windows NT31/12/199916/6/2026
Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability.
ModificadaMedia (4.6)1.8%—Microsoft Windows NT31/12/199916/6/2026
Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.
ModificadaMedia (5)13%—Microsoft Windows NT31/12/199916/6/2026
Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.
ModificadaMedia (5)5.0%—Microsoft Windows NT31/12/199916/6/2026
Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.
ModificadaAlta (7.5)3.9%—Microsoft Windows NT31/12/199916/6/2026
When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies.
ModificadaMedia (4.6)1.4%—Microsoft Windows 2000Microsoft Windows NT31/12/199916/6/2026
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.
ModificadaAlta (7.8)22%—Microsoft Windows NT16/12/199916/6/2026
Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request."
ModificadaMedia (5)7.1%—Microsoft Windows NT16/12/199916/6/2026
Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.
ModificadaMedia (4.6)2.7%💥 ExploitMicrosoft Windows 95Microsoft Windows 98Microsoft Windows NT10/12/199916/6/2026
The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.
ModificadaMedia (5)15%💥 ExploitMicrosoft Windows 2000Microsoft Windows NT1/12/199916/6/2026
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
ModificadaMedia (4.6)1.2%—Microsoft Windows NT30/11/199916/6/2026
A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.
ModificadaAlta (10)4.9%—Microsoft Windows NT18/11/199916/6/2026
Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.
ModificadaMedia (5)21%💥 ExploitMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows NT17/11/199916/6/2026
Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.
ModificadaAlta (7.2)6.7%—Microsoft Windows NT4/11/199916/6/2026
Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.
ModificadaAlta (7.2)3.2%💥 ExploitMicrosoft Windows NT4/11/199916/6/2026
The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.
ModificadaMedia (5)13%—Microsoft Windows NT26/10/199916/6/2026
LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.
ModificadaAlta (7.5)12%—Microsoft Terminal ServerMicrosoft Windows 95Microsoft Windows 98seMicrosoft Windows NT20/9/199916/6/2026
Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.
ModificadaAlta (9)22%💥 ExploitMicrosoft Windows NT17/9/199916/6/2026
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
ModificadaMedia (5)25%—Microsoft Windows NT24/8/199916/6/2026
Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.
ModificadaMedia (6.2)2.9%💥 ExploitMicrosoft Windows 2000Microsoft Windows NT29/7/199916/6/2026
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
ModificadaMedia (5)17%💥 ExploitMicrosoft Windows NT23/7/199916/6/2026
Denial of service in Windows NT messenger service through a long username.
ModificadaAlta (7.8)8.5%—Microsoft Windows 2000Microsoft Windows NT20/7/199916/6/2026
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
ModificadaAlta (7.8)5.8%—Microsoft Windows NT6/7/199916/6/2026
A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.
ModificadaAlta (7.8)26%💥 ExploitMicrosoft Windows 2000Microsoft Windows 95Microsoft Windows 98Microsoft Windows NT3/7/199916/6/2026
Denial of service in various Windows systems via malformed, fragmented IGMP packets.