Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
406 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 41% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows Vista+1 | 12/8/2009 | 16/6/2026 | The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, aka "Telnet Credential Reflection Vulnerability," a… | |
| Modificada | Alta (9.3) | 35% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP | 12/8/2009 | 16/6/2026 | Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2; or 5.2 or 6.1 on Windows XP SP3; allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Remote Desktop… | |
| Modificada | Alta (9.3) | 8.8% | — | Microsoft Windows 2000Microsoft Windows 2003 Server | 12/8/2009 | 16/6/2026 | Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability." | |
| Modificada | Alta (9.3) | 25% | — | Microsoft Windows 2000Microsoft Windows 2003 Server | 12/8/2009 | 16/6/2026 | Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length calculation, aka "WINS Heap Overflow Vulnerability." | |
| Modificada | Alta (8.5) | 22% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP | 12/8/2009 | 16/6/2026 | Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008… | |
| Modificada | Alta (9.3) | 29% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP | 12/8/2009 | 16/6/2026 | Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed header in a crafted AVI file, aka… | |
| Modificada | Alta (8.8) | 21% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP | 12/8/2009 | 16/6/2026 | Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2… | |
| Modificada | Alta (8.8) | 38% | — | Microsoft Visual C++Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2008+3 | 29/7/2009 | 16/6/2026 | The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of… | |
| Modificada | Alta (9.3) | 31% | — | Microsoft Windows 2003 ServerMicrosoft Windows XP | 7/7/2009 | 16/6/2026 | Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2… | |
| Analizada | Alta (8.8) | 77% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 2003 ServerMicrosoft Windows XP | 7/7/2009 | 16/6/2026 | Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows… | |
| Modificada | Alta (10) | 32% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows ServerMicrosoft Windows Server 2008+2 | 10/6/2009 | 16/6/2026 | The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect… | |
| Modificada | Alta (9) | 35% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows ServerMicrosoft Windows Server 2008+2 | 10/6/2009 | 16/6/2026 | The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library… | |
| Modificada | Media (4.9) | 3.9% | 💥 PoC | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows Vista+1 | 10/6/2009 | 16/6/2026 | The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability." | |
| Modificada | Media (4.7) | 1.3% | — | Microsoft Windows 2003 ServerMicrosoft Windows Vista | 1/6/2009 | 16/6/2026 | win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerability than CVE-2008-1084. NOTE: some of these details are… | |
| Analizada | Alta (8.8) | 51% | ⚠ Explotación activa | Microsoft DirectxMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2003+1 | 29/5/2009 | 16/6/2026 | Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May… | |
| Modificada | Alta (9.3) | 34% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 15/4/2009 | 16/6/2026 | Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an… | |
| Modificada | Alta (9.3) | 26% | — | Microsoft Office WordMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 15/4/2009 | 16/6/2026 | Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and the Word 6 text converter in Microsoft Office Word 2000 SP3 and 2002 SP3; allows remote attackers to execute arbitrary code via a crafted Word 6 file that contains malformed… | |
| Modificada | Crítica (9.8) | 14% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows Server 2008+2 | 10/12/2008 | 16/6/2026 | Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be… | |
| Modificada | Alta (9.3) | 31% | — | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Server 2003Microsoft Windows Server 2008+2 | 10/12/2008 | 16/6/2026 | Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WMF file, which triggers a buffer overflow, aka "GDI Integer Overflow Vulnerability." | |
| Modificada | Alta (7.2) | 4.0% | 💥 Exploit | Microsoft Windows 2003 ServerMicrosoft Windows XP | 15/10/2008 | 16/6/2026 | afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths… | |
| Modificada | Alta (9.3) | 55% | 💥 Exploit | Microsoft Windows Media EncoderMicrosoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2003 Server+1 | 11/9/2008 | 16/6/2026 | Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers to execute arbitrary code via a long first argument to the GetDetailsString method, aka "Windows Media Encoder Buffer Overrun Vulnerability." | |
| Modificada | Alta (9) | 36% | — | Microsoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Vista+1 | 13/8/2008 | 16/6/2026 | The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted event subscription request. | |
| Modificada | Alta (9) | 28% | — | Microsoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows Vista+1 | 13/8/2008 | 16/6/2026 | Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that is used to access an array of function pointers. | |
| Modificada | Alta (9.3) | 46% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 13/8/2008 | 16/6/2026 | Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted… | |
| Modificada | Alta (7.1) | 27% | — | Microsoft Windows-ntMicrosoft Windows 2003 ServerMicrosoft Windows XP | 12/6/2008 | 16/6/2026 | Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request. |