Windows 98se

Vendor:

First CVE: Aug 11, 1999 · Active for 26 years

71
Total CVEs
More Total CVEs than 98% of tracked products
7.9
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Windows 98se over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 11, 1999
26 years ago
Most Recent CVE
Jul 24, 2007
6,940 days ago

CVE Severity & Scoring

Windows 98se71 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (1.4%)
Network1 (1.4%)
Unknown69 (97.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (2.8%)
High0 (0.0%)
Unknown69 (97.2%)
User Interaction
None1 (1.4%)
Unknown69 (97.2%)
Required1 (1.4%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (2.8%)
Unknown69 (97.2%)

Top CVEs

Signals from CVEs in this product scope (71 CVEs).

71 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.
May 2, 200510.081NOYES
Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_
Nov 23, 200410.081NOYES
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by
Aug 18, 20045.074NOYES
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-rese
Apr 12, 20055.072NOYES
Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Play
Feb 14, 20069.362NOYES
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
May 2, 20057.561NOYES
Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY directive with a long Location URL.
Dec 20, 20017.557NOYES
The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by mo
May 2, 20057.554NOYES
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access
Dec 19, 20006.454NOYES
Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 all
Aug 10, 20057.553NOYES

Exploit Exposure

Signals from CVEs in this product scope (71 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.4% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
27 CVEs
38.0% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (71 CVEs).

Media Mentions

Signals from CVEs in this product scope (71 CVEs).

Top CNAs Publishing CVEs For Windows 98se

Top CWEs

Versions

No cataloged versions.