Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
283 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 1.5% | — | Microsoft Windows NT | 31/12/1999 | 16/6/2026 | Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle. | |
| Modificada | Alta (7.5) | 18% | — | Microsoft Windows NT | 31/12/1999 | 16/6/2026 | Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability. | |
| Modificada | Media (4.6) | 1.8% | — | Microsoft Windows NT | 31/12/1999 | 16/6/2026 | Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device. | |
| Modificada | Media (5) | 13% | — | Microsoft Windows NT | 31/12/1999 | 16/6/2026 | Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface. | |
| Modificada | Media (5) | 5.0% | — | Microsoft Windows NT | 31/12/1999 | 16/6/2026 | Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup. | |
| Modificada | Alta (7.5) | 3.9% | — | Microsoft Windows NT | 31/12/1999 | 16/6/2026 | When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies. | |
| Modificada | Media (4.6) | 1.4% | — | Microsoft Windows 2000Microsoft Windows NT | 31/12/1999 | 16/6/2026 | When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only. | |
| Modificada | Alta (7.8) | 22% | — | Microsoft Windows NT | 16/12/1999 | 16/6/2026 | Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request." | |
| Modificada | Media (5) | 7.1% | — | Microsoft Windows NT | 16/12/1999 | 16/6/2026 | Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords. | |
| Modificada | Media (4.6) | 2.7% | 💥 Exploit | Microsoft Windows 95Microsoft Windows 98Microsoft Windows NT | 10/12/1999 | 16/6/2026 | The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed. | |
| Modificada | Media (5) | 15% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows NT | 1/12/1999 | 16/6/2026 | NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it. | |
| Modificada | Media (4.6) | 1.2% | — | Microsoft Windows NT | 30/11/1999 | 16/6/2026 | A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users. | |
| Modificada | Alta (10) | 4.9% | — | Microsoft Windows NT | 18/11/1999 | 16/6/2026 | Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name. | |
| Modificada | Media (5) | 21% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 98Microsoft Windows NT | 17/11/1999 | 16/6/2026 | Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word. | |
| Modificada | Alta (7.2) | 6.7% | — | Microsoft Windows NT | 4/11/1999 | 16/6/2026 | Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request. | |
| Modificada | Alta (7.2) | 3.2% | 💥 Exploit | Microsoft Windows NT | 4/11/1999 | 16/6/2026 | The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider. | |
| Modificada | Media (5) | 13% | — | Microsoft Windows NT | 26/10/1999 | 16/6/2026 | LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo. | |
| Modificada | Alta (7.5) | 12% | — | Microsoft Terminal ServerMicrosoft Windows 95Microsoft Windows 98seMicrosoft Windows NT | 20/9/1999 | 16/6/2026 | Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability. | |
| Modificada | Alta (9) | 22% | 💥 Exploit | Microsoft Windows NT | 17/9/1999 | 16/6/2026 | The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager. | |
| Modificada | Media (5) | 25% | — | Microsoft Windows NT | 24/8/1999 | 16/6/2026 | Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking. | |
| Modificada | Media (6.2) | 2.9% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows NT | 29/7/1999 | 16/6/2026 | Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file. | |
| Modificada | Media (5) | 17% | 💥 Exploit | Microsoft Windows NT | 23/7/1999 | 16/6/2026 | Denial of service in Windows NT messenger service through a long username. | |
| Modificada | Alta (7.8) | 8.5% | — | Microsoft Windows 2000Microsoft Windows NT | 20/7/1999 | 16/6/2026 | Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request. | |
| Modificada | Alta (7.8) | 5.8% | — | Microsoft Windows NT | 6/7/1999 | 16/6/2026 | A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them. | |
| Modificada | Alta (7.8) | 26% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 95Microsoft Windows 98Microsoft Windows NT | 3/7/1999 | 16/6/2026 | Denial of service in various Windows systems via malformed, fragmented IGMP packets. |