Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3189▲ 608 respecto a la semana anterior
Críticas / altas1510▲ 105 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 71% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 4/7/2001 | 16/6/2026 | Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that… | |
| Modificada | Alta (7.2) | 0.36% | — | Cisco Content Services Switch 11050Cisco Content Services Switch 11150Cisco Content Services Switch 11800 | 18/6/2001 | 16/6/2026 | Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode. | |
| Modificada | Media (5) | 37% | — | Microsoft Exchange ServerMicrosoft Internet Information Services | 2/6/2001 | 16/6/2026 | IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's. | |
| Modificada | Media (5) | 68% | 💥 Exploit | Microsoft Internet Information Services | 2/6/2001 | 16/6/2026 | IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests. | |
| Modificada | Media (5) | 17% | — | Microsoft Windows Media Services | 12/2/2001 | 16/6/2026 | Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the "Severed Windows Media Server Connection" vulnerability. | |
| Modificada | Baja (2.1) | 0.29% | — | Cisco ArrowpointCisco Content Services Switch | 12/2/2001 | 16/6/2026 | Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands. | |
| Modificada | Media (5) | 20% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 12/2/2001 | 16/6/2026 | FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability. | |
| Modificada | Media (5) | 28% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 12/2/2001 | 16/6/2026 | IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability. | |
| Modificada | Baja (2.1) | 0.52% | — | Cisco ArrowpointCisco Content Services Switch | 12/2/2001 | 16/6/2026 | Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Media (5) | 1.3% | — | Ptlink IRC ServicesPtlink Ircd | 9/1/2001 | 16/6/2026 | PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode +owgscfxeb" and "oper" commands. | |
| Modificada | Alta (7.5) | 5.6% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 9/1/2001 | 16/6/2026 | Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same… | |
| Modificada | Media (5) | 44% | 💥 Exploit | Microsoft Internet Information Services | 19/12/2000 | 23/9/2026 | Una mala configuración en IIS 5.0 con Index Server habilitado y la propiedad Index establecida permite a atacantes remotos listar directorios en la raíz web a través de una búsqueda de Web Distributed Authoring and Versioning (WebDAV). | |
| Modificada | Alta (7.5) | 46% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 19/12/2000 | 23/9/2026 | Las páginas .ASP de IIS 4.0 y 5.0 envían la misma cookie de ID de sesión para sesiones web seguras e inseguras, lo que podría permitir a atacantes remotos secuestrar la sesión web segura del usuario si ese usuario se mueve a una sesión insegura, también conocida como la vulnerabilidad 'Session ID Cookie Marking'. | |
| Modificada | Alta (7.5) | 69% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 19/12/2000 | 23/9/2026 | IIS 5.0 permite a atacantes remotos ejecutar comandos arbitrarios a través de una solicitud malformada para un archivo ejecutable cuyo nombre se adjunta con comandos del sistema operativo, también conocida como la vulnerabilidad 'Web Server File Request Parsing'. | |
| Modificada | Alta (7.5) | 63% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 19/12/2000 | 23/9/2026 | IIS 4.0 y 5.0 permite a atacantes remotos leer documentos fuera de la raíz web, y posiblemente ejecutar comandos arbitrarios, a través de URLs malformadas que contienen caracteres codificados en UNICODE, también conocida como la vulnerabilidad de 'recorrido de carpetas del servidor web'. | |
| Modificada | Baja (2.6) | 15% | — | Microsoft Windows Media Services | 14/11/2000 | 16/6/2026 | Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability. | |
| Modificada | Media (6.4) | 15% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 20/10/2000 | 16/6/2026 | IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability. | |
| Modificada | Media (5) | 87% | 💥 Exploit | Microsoft Internet Information Services | 20/10/2000 | 16/6/2026 | IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability. | |
| Modificada | Alta (7.5) | 10% | — | Microsoft FrontpageMicrosoft Internet Information ServerMicrosoft Internet Information Services | 20/10/2000 | 16/6/2026 | Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same… | |
| Modificada | Media (5) | 68% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 17/7/2000 | 16/6/2026 | IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability. | |
| Modificada | Media (5) | 25% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 14/7/2000 | 16/6/2026 | An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability. | |
| Modificada | Baja (2.6) | 77% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 13/7/2000 | 16/6/2026 | IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined. | |
| Modificada | Alta (10) | 4.5% | 💥 Exploit | Netscape Professional Services Ftpserver | 21/6/2000 | 16/6/2026 | Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Media (5) | 32% | 💥 Exploit | Microsoft Windows Media Services | 30/5/2000 | 16/6/2026 | Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder Request" vulnerability. | |
| Modificada | Media (5) | 58% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 11/5/2000 | 16/6/2026 | IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability. |