Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3146▲ 578 respecto a la semana anterior
Críticas / altas1455▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
2265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 12% | — | Microsoft Windows 2000 Terminal Services | 26/7/2002 | 16/6/2026 | Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass… | |
| Modificada | Alta (7.5) | 31% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 3/7/2002 | 16/6/2026 | Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise." | |
| Modificada | Media (5) | 27% | — | Microsoft Internet Information ServicesMicrosoft SQL ServerMicrosoft Windows 2000 | 16/5/2002 | 16/6/2026 | El MSDTC (Microsoft Distributed Transaction Service Coordinator) para MS Windows 2000, MS IIS 5.0 y SQL Server 6.5 a 2000 permite a atacantes remotos causar una denegación de servicio (caída o cuelgue) mediante entradas malformadas (aleatorias). | |
| Modificada | Alta (7.5) | 34% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 22/4/2002 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (Cross-site scripting) en Internet Information Server 4.0, 5.0 y 5.1 permite a atacantes remotos ejecutar scripts arbitrarios como otros usuarios del web mediante el mensaje de error usado en una redirección de URL. | |
| Modificada | Alta (7.5) | 64% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 22/4/2002 | 16/6/2026 | Vulnerabildad de secuencias de comandos en sitios cruzados (cross-site scripting) en Internet Information Server (IIS) 4.0, 5.0 y 5.1 permite a atacantes remotos ejecutar código arbitrario como otros usuarios mediatne una página de error HTTP. | |
| Modificada | Alta (7.5) | 34% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 22/4/2002 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (Cross-site scripting) en el fichero de Ayuda del Internet Information Server (IIS) 4.0, 5.0 y 5.1 permite a atacantes remotos insertar código en otra sesión de usuario. | |
| Modificada | Alta (7.5) | 49% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 22/4/2002 | 16/6/2026 | Desbordamiento de buffer en Internet Information Server (IIS) 4.0, 5.0 y 5.1 permite a atacantes remotos falsificar la comprobación de seguridad de cabeceras HTTP y causar una denegación de servicio o ejecutar código arbitrario mediante valores de campos de las cabeceras HTTP. | |
| Modificada | Alta (7.5) | 34% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 22/4/2002 | 16/6/2026 | Desbordamiento de buffer la extensión ISAPI ism.dll que implementa los scripts HTR en MS Internet Information Server (IIS) 4.0 y 5.0 permite a atacantes causar una denegación de servido o ejecutar código arbitrario mediante peticiones HTR con nombres de variables largos. | |
| Modificada | Media (5) | 56% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 22/4/2002 | 16/6/2026 | El servicio FTP en Intenet Information Server (IIS) 4.0, 5.0 y 5.1 permite a atacantes que han establecido una sesión FTP causar una denegación de servicio mediante una petición de estado especialmente formada. | |
| Modificada | Media (5) | 57% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 22/4/2002 | 16/6/2026 | Un filtro ISAPI en las Extensiones de Servidor de Front Page y ASP.NET para Internet Information Server (IIS) 4.0, 5.0 y 5.1 no maneja adecuadamente la condición de error cuando se provee una URL larga, lo que permite a atacantes remotos causar una denegación de sevicio (caída). | |
| Modificada | Alta (7.5) | 63% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 22/4/2002 | 16/6/2026 | Desbordamiento de buffer en las funciones de inclusión de ficheros en el servidor (server-side include) de ASP en IIS 4.0, 5.0 y 5.1 permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario mediante nombres de fichero largos. | |
| Modificada | Alta (7.5) | 62% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 22/4/2002 | 16/6/2026 | Desbordamiento de buffer en el mecanismo de transferencia de datos de Internet Information Server (IIS) 4.0, 5.0 y 5.1 permite a atacantes remotos causar una denegación de servicio o ejecutar código, tambien conocido como "Variante del desbordamiento de buffer en codificación troceada" | |
| Modificada | Alta (7.5) | 77% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 22/4/2002 | 16/6/2026 | Desbordamiento de buffer en el mecanismo de transferencia de codificación troceada (chunked encoding) en Active Server Pages (ASP) de Internet Information Server (IIS) 4.0 y 5.0, que permite a atacantes causar una denegación de servicio o ejecutar código arbitrario. | |
| Modificada | Media (5) | 2.0% | — | MDG Computer Services WEB Server 4D Ecommerce | 25/3/2002 | 16/6/2026 | MDG Computer Services Web Server WS4D/eCommerce 3.5.3, permite a atacantes remotos explotar directorios via ../ conteniendo / en la parte codificada de la peticion HTTP. | |
| Modificada | Alta (7.5) | 3.3% | — | MDG Computer Services WEB Server 4D Ecommerce | 25/3/2002 | 16/6/2026 | MDG Computer Services Web Server 4D WS4D/eCommerce 3.0 y anteriores, y posiblemente 3.5.3, permiten a atacantes remotos causar negaciones de servicio y posiblemente ejecutar comandos arbitrarios vía peticiones largas HTTP. | |
| Modificada | Media (5) | 19% | — | Microsoft Internet ExplorerMicrosoft SQL ServerMicrosoft XML Core ServicesMicrosoft Windows XP | 8/3/2002 | 16/6/2026 | El control XMLHTTP en Microsoft XML Core Services 2.6 y versiones posteriores no manejan adecuadamente el establecimiento de valores de la Zona de Seguridad del IE, lo cual permite a atacantes remotos la lectura arbitraria de ficheros especificando un fichero local como una fuente de datos XML. | |
| Modificada | Media (5) | 35% | 💥 Exploit | Microsoft Internet Information Services | 11/12/2001 | 16/6/2026 | Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection. | |
| Modificada | Alta (7.5) | 19% | — | Microsoft Internet Information Services | 20/11/2001 | 16/6/2026 | Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters. | |
| Modificada | Baja (2.1) | 2.4% | — | Microsoft Internet Information Services | 30/10/2001 | 16/6/2026 | IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type table. | |
| Modificada | Media (5) | 33% | — | Microsoft Services | 30/10/2001 | 16/6/2026 | Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service. | |
| Modificada | Alta (7.2) | 69% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 20/9/2001 | 16/6/2026 | Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability. | |
| Modificada | Media (5) | 27% | — | Microsoft Internet Information Services | 20/9/2001 | 16/6/2026 | Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request. | |
| Modificada | Alta (7.2) | 8.8% | 💥 Exploit | Microsoft Internet Information Services | 20/9/2001 | 16/6/2026 | IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability. | |
| Modificada | Alta (7.5) | 1.6% | — | Cisco Content Services Switch 11000 | 14/8/2001 | 16/6/2026 | The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the interface. | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Content Services Switch 11000 | 14/8/2001 | 16/6/2026 | The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands. |