Windows 98

Vendor:

First CVE: Jan 25, 1999 · Active for 27 years

101
Total CVEs
More Total CVEs than 99% of tracked products
9.2
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Windows 98 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 25, 1999
27 years ago
Most Recent CVE
Nov 24, 2020
2,068 days ago

CVE Severity & Scoring

Windows 98101 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local2 (2.0%)
Network2 (2.0%)
Unknown97 (96.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (4.0%)
High0 (0.0%)
Unknown97 (96.0%)
User Interaction
None1 (1.0%)
Unknown97 (96.0%)
Required3 (3.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (4.0%)
Unknown97 (96.0%)

Top CVEs

Signals from CVEs in this product scope (101 CVEs).

101 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a,
Jun 1, 20047.584NOYES
Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.
May 2, 200510.081NOYES
Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arb
Nov 3, 20047.581NOYES
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4,
Jun 1, 20047.579NOYES
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by
Aug 18, 20045.074NOYES
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-rese
Apr 12, 20055.072NOYES
Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of serv
Nov 3, 200410.063NOYES
Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Play
Feb 14, 20069.362NOYES
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
May 2, 20057.561NOYES
Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY directive with a long Location URL.
Dec 20, 20017.557NOYES

Exploit Exposure

Signals from CVEs in this product scope (101 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
4.0% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
41 CVEs
40.6% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (101 CVEs).

Media Mentions

Signals from CVEs in this product scope (101 CVEs).

Top CNAs Publishing CVEs For Windows 98

Top CWEs

Versions

No cataloged versions.