threat
engine
.sh
Back
·
··:··
Home
/
Product
/
microsoft windows nt
Product
microsoft windows nt
267 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2008-5232
all versions
Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Win
CVE-2008-3014
all versions
Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vist
CVE-2008-3012
all versions
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Ser
CVE-2008-3008
all versions
Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series all
CVE-2007-5348
all versions
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1
CVE-2008-1457
all versions
The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does
CVE-2008-1456
all versions
Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold a
CVE-2008-2246
all versions
Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 dom
CVE-2008-1435
all versions
Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary
CVE-2008-1453
all versions
The Bluetooth stack in Microsoft Windows XP SP2 and SP3, and Vista Gold and SP1, allows physically proximate attackers to execute
CVE-2008-1445
all versions
Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allow
CVE-2008-1436
all versions
Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkServi
CVE-2008-0927
all versions
dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption)
CVE-2008-1087
all versions
Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows r
CVE-2008-1086
all versions
The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 200
CVE-2007-6026
all versions
Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Of
CVE-2007-1973
all versions
Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify mem
CVE-2007-1912
all versions
Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP
CVE-2006-2379
all versions
Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allow
CVE-2006-1184
all versions
Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote
CVE-2006-0034
all versions
Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction
CVE-2006-1591
all versions
Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to execute arbitrary code via cra
CVE-2006-0988
all versions
The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service
CVE-2006-0005
all versions
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explor
CVE-2006-0010
all versions
Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, an
CVE-2005-4717
all versions
Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003
CVE-2005-2827
all versions
The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory
CVE-2005-2150
all versions
Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain al
CVE-2005-1935
all versions
Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to exec
CVE-2005-1184
all versions
The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP pa
CVE-2005-0050
all versions
The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the len
CVE-2005-0045
all versions
The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB
CVE-2005-0416
all versions
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 all
CVE-2004-1080
all versions
The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attacke
CVE-2004-0901
all versions
Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, whic
CVE-2004-0900
all versions
The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of c
CVE-2004-0899
all versions
The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not prope
CVE-2004-0893
all versions
The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 20
CVE-2004-0571
all versions
Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute
CVE-2004-0568
all versions
HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the len
CVE-2004-1306
all versions
Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allow
CVE-2004-1049
all versions
Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code vi
CVE-2004-0567
all versions
The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 an
CVE-2004-1361
all versions
Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote
CVE-2004-1305
all versions
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 all
CVE-2004-0574
all versions
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003,
CVE-2004-0569
all versions
The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (s
CVE-2004-0208
all versions
The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows loca
CVE-2004-0207
all versions
"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows N
CVE-2004-0206
all versions
Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Se
CVE-2004-0212
all versions
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local
CVE-2004-0210
all versions
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters,
7.8
HIGH
CVE-2004-0201
all versions
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Serve
CVE-2003-1048
all versions
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of
7.8
HIGH
CVE-2004-0124
all versions
The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communicat
CVE-2004-0123
all versions
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allow
CVE-2004-0118
all versions
The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system str
CVE-2003-0910
all versions
The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000
CVE-2003-0906
all versions
Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows
CVE-2003-0807
all versions
Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0
CVE-2003-0806
all versions
Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a
CVE-2003-0719
all versions
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Mic
CVE-2003-0533
all versions
Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem
CVE-2003-0825
all versions
The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not pr
CVE-2003-0818
all versions
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executa
CVE-2003-1407
all versions
Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the c
CVE-2003-0813
all versions
A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to
CVE-2003-0717
all versions
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote a
CVE-2003-0711
all versions
Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 a
CVE-2003-0660
all versions
The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX c
CVE-2003-0659
all versions
Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via lon
CVE-2003-0661
all versions
The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to
CVE-2003-0715
all versions
Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers
CVE-2003-0528
all versions
Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers
CVE-2003-0525
all versions
The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attac
CVE-2003-0352
all versions
Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers
CVE-2003-0345
all versions
Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service
CVE-2003-0469
all versions
Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial
CVE-2003-0227
all versions
The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Micr
CVE-2003-0112
all versions
Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugg
CVE-2002-1561
all versions
The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled R
CVE-2003-0010
all versions
Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows op
CVE-2003-0003
all versions
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and
CVE-2002-2401
all versions
NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable fil
CVE-2002-2073
all versions
Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote att
CVE-2002-2028
all versions
The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid pas
CVE-2002-1712
all versions
Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/I
CVE-2002-1325
all versions
Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java
CVE-2002-1260
all versions
The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass
CVE-2002-1258
all versions
Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other a
CVE-2002-1257
all versions
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a
CVE-2002-1183
all versions
Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote atta
CVE-2002-1184
all versions
The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in
CVE-2002-0863
all versions
Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plain
CVE-2002-0694
all versions
The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Win
CVE-2002-0693
all versions
Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4
CVE-2002-0862
all versions
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Micros
CVE-2002-0699
all versions
Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Mi
CVE-2002-0724
all versions
Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to c
CVE-2002-0725
all versions
NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to th
5.5
MEDIUM
CVE-2002-0421
all versions
IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password cha
CVE-2002-0391
all versions
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC in
9.8
CRITICAL
CVE-2002-0366
all versions
Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS)
CVE-2002-0367
all versions
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs
7.8
HIGH
CVE-2002-0151
all versions
Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of serv
CVE-2002-0070
all versions
Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary cod
CVE-2002-0053
all versions
Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers
CVE-2002-0018
all versions
In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not
CVE-2001-0879
all versions
Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service.
CVE-2001-0663
all versions
Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remo
CVE-2001-0662
all versions
RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed
CVE-2001-0543
all versions
Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaus
CVE-2001-0509
all versions
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) W
CVE-2001-1452
all versions
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, whi
7.5
HIGH
CVE-2000-1200
all versions
Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy po
CVE-2001-1122
all versions
Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by
CVE-2001-1288
all versions
Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt
CVE-2001-0341
all versions
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to exe
CVE-2001-1244
all versions
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting t
CVE-2001-0238
all versions
Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Z
CVE-2001-0373
all versions
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-
CVE-2001-0281
all versions
Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through
CVE-2001-0017
<= 4.0
Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka
CVE-2001-0016
<= 4.0
NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow
CVE-2001-0047
all versions
The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify
CVE-2001-0046
all versions
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify
CVE-2001-0045
all versions
The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by chang
CVE-2001-0006
all versions
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local u
7.1
HIGH
CVE-2001-0003
all versions
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer secur
CVE-2000-1149
all versions
Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a l
CVE-2000-1089
all versions
Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buff
CVE-2000-1039
all versions
Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with
CVE-2000-1227
all versions
Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending mul
CVE-2000-0885
all versions
Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Nam
CVE-1999-1579
all versions
The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allo
CVE-2000-0858
all versions
Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of ma
CVE-2000-1079
all versions
Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote a
CVE-2000-0673
all versions
The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of servic
CVE-2000-0663
all versions
The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which
CVE-1999-0585
all versions
A Windows NT administrator account has the default name of Administrator.
CVE-2000-0377
all versions
The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request
CVE-2000-0544
all versions
Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests th
CVE-1999-0590
all versions
A system does not present an appropriate legal message or warning to a user who is accessing it.
CVE-2000-0404
all versions
The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Mast
CVE-2000-0403
all versions
The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large numbe
CVE-2000-0305
all versions
Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of ser
CVE-1999-0980
all versions
Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resour
CVE-2000-0331
all versions
Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of
CVE-2000-0256
all versions
Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that
CVE-2000-1218
all versions
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching par
9.8
CRITICAL
CVE-2000-0259
all versions
The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users
CVE-1999-0701
all versions
After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Adm
CVE-2000-0232
all versions
Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed T
CVE-2000-0155
all versions
Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate prog
CVE-2000-0197
all versions
The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the
CVE-2000-0129
all versions
Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by perf
CVE-2000-0089
all versions
The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file wit
CVE-2000-0121
all versions
The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with
CVE-1999-0595
all versions
A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.
CVE-2000-0070
all versions
NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC Port Requ
CVE-1999-1455
<= 4.0
RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a
CVE-1999-1452
all versions
GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the
CVE-1999-1364
all versions
Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) Get
CVE-1999-1363
all versions
Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of
CVE-1999-1362
<= 4.0
Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K function
CVE-1999-1360
all versions
Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in
CVE-1999-1359
all versions
When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce polic
CVE-1999-1358
all versions
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfi
CVE-1999-1317
<= 4.0
Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder
CVE-1999-1316
all versions
Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an
CVE-1999-1294
all versions
Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Man
CVE-1999-1222
all versions
Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the I
CVE-1999-1157
<= 4.0
Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Reques
CVE-1999-1132
all versions
Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing In
CVE-1999-1127
all versions
Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of
7.5
HIGH
CVE-1999-1084
all versions
The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan
CVE-1999-0815
<= 4.0
Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion)
CVE-1999-0995
all versions
Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaL
CVE-1999-0994
all versions
Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwor
CVE-1999-0975
all versions
The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a
CVE-1999-0819
all versions
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
CVE-1999-0824
all versions
A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allo
CVE-1999-0987
all versions
Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domai
CVE-2000-0073
all versions
Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control w
CVE-1999-0899
all versions
The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the
CVE-1999-0898
all versions
Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malf
CVE-1999-1234
all versions
LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) S
CVE-1999-0909
all versions
Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options
CVE-1999-0886
all versions
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
CVE-2000-0328
all versions
Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing
CVE-1999-0700
all versions
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
CVE-1999-0224
all versions
Denial of service in Windows NT messenger service through a long username.
CVE-1999-0721
all versions
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
CVE-1999-0728
all versions
A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.
CVE-1999-0918
all versions
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
CVE-1999-0726
all versions
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
CVE-1999-0140
all versions
Denial of service in RAS/PPTP on NT systems.
CVE-1999-1365
all versions
Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as N
CVE-1999-0723
all versions
The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting
CVE-1999-0874
all versions
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC,
CVE-1999-0755
all versions
Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.
CVE-1999-0715
all versions
Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a ma
CVE-1999-0716
all versions
Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.
CVE-1999-0489
all versions
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a varian
CVE-1999-0717
all versions
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
CVE-1999-0444
all versions
Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display fo
CVE-1999-0382
all versions
The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run prog
CVE-1999-1254
all versions
Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, w
CVE-1999-0376
all versions
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.
CVE-1999-0372
all versions
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
CVE-1999-0366
all versions
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with
CVE-1999-0119
all versions
Windows NT 4.0 beta allows users to read and delete shares.
CVE-1999-0391
all versions
The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the r
CVE-1999-0593
all versions
The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a
CVE-1999-0581
all versions
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.
CVE-1999-0579
all versions
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
CVE-1999-0578
all versions
A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.
CVE-1999-0577
all versions
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
CVE-1999-0570
all versions
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.
CVE-1999-0560
all versions
A system-critical Windows NT file or directory has inappropriate permissions.
CVE-1999-0549
all versions
Windows NT automatically logs in an administrator upon rebooting.
CVE-1999-0384
all versions
The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard w
CVE-1999-0285
all versions
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
CVE-1999-0226
all versions
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
CVE-1999-1291
all versions
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections b
CVE-1999-0546
all versions
The Windows NT guest account is enabled.
CVE-1999-0506
all versions
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
CVE-1999-0505
all versions
A Windows NT domain user or administrator account has a guessable password.
CVE-1999-0969
all versions
The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which genera
CVE-1999-0344
all versions
NT users can gain debug-level access on a system process using the Sechole exploit.
CVE-1999-0288
all versions
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination)
CVE-1999-0278
all versions
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
CVE-1999-1361
all versions
Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resourc
CVE-1999-0225
all versions
Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data siz
CVE-1999-0258
all versions
Bonk variation of teardrop IP fragmentation denial of service.
CVE-1999-0256
all versions
Buffer overflow in War FTP allows remote execution of commands.
CVE-1999-1581
all versions
Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote a
CVE-1999-0104
all versions
A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.
CVE-1999-0015
all versions
Teardrop IP denial of service.
CVE-1999-0016
all versions
Land IP denial of service.
CVE-1999-1217
all versions
The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Tro
CVE-1999-1463
<= 4.0
Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending
CVE-1999-0153
all versions
Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
CVE-1999-0074
all versions
Listening TCP ports are sequentially allocated, allowing spoofing attacks.
CVE-1999-0275
all versions
Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.
CVE-1999-0227
all versions
Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.
CVE-1999-1387
all versions
Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as
CVE-1999-0292
all versions
Denial of service through Winpopup using large user names.
CVE-1999-0612
all versions
A version of finger is running that exposes valid user information to any entity on the network.
CVE-1999-0228
all versions
Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.
CVE-1999-0582
all versions
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad lo
CVE-1999-0576
all versions
A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.
CVE-1999-0575
all versions
A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Acces
CVE-1999-0572
all versions
.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.
CVE-1999-0562
all versions
The registry in Windows NT can be accessed remotely by users who are not administrators.
CVE-1999-0535
all versions
A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, o
CVE-1999-0534
all versions
A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create
CVE-1999-0519
all versions
A NETBIOS/SMB share password is the default, null, or missing.
CVE-1999-0511
all versions
IP forwarding is enabled on a machine which is not a router or firewall.
9.1
CRITICAL
CVE-1999-0504
all versions
A Windows NT local user or administrator account has a default, null, blank, or missing password.
CVE-1999-0503
all versions
A Windows NT local user or administrator account has a guessable password.
CVE-1999-0499
all versions
NETBIOS share information may be published through SNMP registry keys in NT.
CVE-1999-0496
all versions
A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions
CVE-1999-0274
all versions
Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.
CVE-1999-0249
all versions
Windows NT RSHSVC program allows remote users to execute arbitrary commands.
CVE-1999-0179
all versions
Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.
CVE-1999-0077
all versions
Predictable TCP sequence numbers allow spoofing.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin