Windows Me

Vendor:

First CVE: Dec 19, 2000 · Active for 25 years

73
Total CVEs
More Total CVEs than 99% of tracked products
7.3
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Windows Me over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2000
25 years ago
Most Recent CVE
Nov 24, 2020
2,068 days ago

CVE Severity & Scoring

Windows Me73 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local2 (2.7%)
Network1 (1.4%)
Unknown70 (95.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (4.1%)
High0 (0.0%)
Unknown70 (95.9%)
User Interaction
None0 (0.0%)
Unknown70 (95.9%)
Required3 (4.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (4.1%)
Unknown70 (95.9%)

Top CVEs

Signals from CVEs in this product scope (73 CVEs).

73 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a,
Jun 1, 20047.584NOYES
Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_
Nov 23, 200410.081NOYES
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4,
Jun 1, 20047.579NOYES
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-rese
Apr 12, 20055.072NOYES
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer ov
Nov 17, 20037.567NOYES
Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of serv
Nov 3, 200410.063NOYES
Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Play
Feb 14, 20069.362NOYES
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
May 2, 20057.561NOYES
Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY directive with a long Location URL.
Dec 20, 20017.557NOYES
The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by mo
May 2, 20057.554NOYES

Exploit Exposure

Signals from CVEs in this product scope (73 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
2.7% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
28 CVEs
38.4% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (73 CVEs).

Media Mentions

Signals from CVEs in this product scope (73 CVEs).

Top CNAs Publishing CVEs For Windows Me

Top CWEs

Versions

No cataloged versions.