Windows Me
Vendor:
First CVE: Dec 19, 2000 · Active for 25 years
73
Total CVEs
More Total CVEs than 99% of tracked products
7.3
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Windows Me over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2000
25 years ago
Most Recent CVE
Nov 24, 2020
2,068 days ago
CVE Severity & Scoring
Windows Me73 CVEs
40%
60%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (2.7%)
Network1 (1.4%)
Unknown70 (95.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (4.1%)
High0 (0.0%)
Unknown70 (95.9%)
User Interaction
None0 (0.0%)
Unknown70 (95.9%)
Required3 (4.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (4.1%)
Unknown70 (95.9%)
Top CVEs
Signals from CVEs in this product scope (73 CVEs).
73 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0533HIGH Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, | Jun 1, 2004 | 7.5 | 84 | NO | YES |
CVE-2004-0597HIGH Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_ | Nov 23, 2004 | 10.0 | 81 | NO | YES |
CVE-2003-0719HIGH Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, | Jun 1, 2004 | 7.5 | 79 | NO | YES |
CVE-2004-0790MEDIUM Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-rese | Apr 12, 2005 | 5.0 | 72 | NO | YES |
CVE-2003-0717HIGH The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer ov | Nov 17, 2003 | 7.5 | 67 | NO | YES |
CVE-2004-0214HIGH Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of serv | Nov 3, 2004 | 10.0 | 63 | NO | YES |
CVE-2006-0006HIGH Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Play | Feb 14, 2006 | 9.3 | 62 | NO | YES |
CVE-2005-0053HIGH Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability." | May 2, 2005 | 7.5 | 61 | NO | YES |
CVE-2001-0876HIGH Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY directive with a long Location URL. | Dec 20, 2001 | 7.5 | 57 | NO | YES |
CVE-2005-0063HIGH The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by mo | May 2, 2005 | 7.5 | 54 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (73 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
2.7% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
28 CVEs
38.4% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (73 CVEs).
Media Mentions
Signals from CVEs in this product scope (73 CVEs).
Top CNAs Publishing CVEs For Windows Me
Top CWEs
Versions
No cataloged versions.