Home/Product/microsoft windows nt
Product

microsoft windows nt

267 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2008-5232
all versions
Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Win
CVE-2008-3014
all versions
Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vist
CVE-2008-3012
all versions
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Ser
CVE-2008-3008
all versions
Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series all
CVE-2007-5348
all versions
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1
CVE-2008-1457
all versions
The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does
CVE-2008-1456
all versions
Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold a
CVE-2008-2246
all versions
Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 dom
CVE-2008-1435
all versions
Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary
CVE-2008-1453
all versions
The Bluetooth stack in Microsoft Windows XP SP2 and SP3, and Vista Gold and SP1, allows physically proximate attackers to execute
CVE-2008-1445
all versions
Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allow
CVE-2008-1436
all versions
Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkServi
CVE-2008-0927
all versions
dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption)
CVE-2008-1087
all versions
Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows r
CVE-2008-1086
all versions
The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 200
CVE-2007-6026
all versions
Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Of
CVE-2007-1973
all versions
Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify mem
CVE-2007-1912
all versions
Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP
CVE-2006-2379
all versions
Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allow
CVE-2006-1184
all versions
Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote
CVE-2006-0034
all versions
Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction
CVE-2006-1591
all versions
Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to execute arbitrary code via cra
CVE-2006-0988
all versions
The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service
CVE-2006-0005
all versions
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explor
CVE-2006-0010
all versions
Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, an
CVE-2005-4717
all versions
Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003
CVE-2005-2827
all versions
The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory
CVE-2005-2150
all versions
Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain al
CVE-2005-1935
all versions
Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to exec
CVE-2005-1184
all versions
The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP pa
CVE-2005-0050
all versions
The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the len
CVE-2005-0045
all versions
The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB
CVE-2005-0416
all versions
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 all
CVE-2004-1080
all versions
The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attacke
CVE-2004-0901
all versions
Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, whic
CVE-2004-0900
all versions
The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of c
CVE-2004-0899
all versions
The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not prope
CVE-2004-0893
all versions
The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 20
CVE-2004-0571
all versions
Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute
CVE-2004-0568
all versions
HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the len
CVE-2004-1306
all versions
Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allow
CVE-2004-1049
all versions
Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code vi
CVE-2004-0567
all versions
The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 an
CVE-2004-1361
all versions
Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote
CVE-2004-1305
all versions
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 all
CVE-2004-0574
all versions
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003,
CVE-2004-0569
all versions
The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (s
CVE-2004-0208
all versions
The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows loca
CVE-2004-0207
all versions
"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows N
CVE-2004-0206
all versions
Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Se
CVE-2004-0212
all versions
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local
CVE-2004-0210
all versions
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters,
7.8HIGH
CVE-2004-0201
all versions
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Serve
CVE-2003-1048
all versions
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of
7.8HIGH
CVE-2004-0124
all versions
The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communicat
CVE-2004-0123
all versions
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allow
CVE-2004-0118
all versions
The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system str
CVE-2003-0910
all versions
The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000
CVE-2003-0906
all versions
Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows
CVE-2003-0807
all versions
Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0
CVE-2003-0806
all versions
Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a
CVE-2003-0719
all versions
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Mic
CVE-2003-0533
all versions
Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem
CVE-2003-0825
all versions
The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not pr
CVE-2003-0818
all versions
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executa
CVE-2003-1407
all versions
Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the c
CVE-2003-0813
all versions
A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to
CVE-2003-0717
all versions
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote a
CVE-2003-0711
all versions
Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 a
CVE-2003-0660
all versions
The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX c
CVE-2003-0659
all versions
Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via lon
CVE-2003-0661
all versions
The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to
CVE-2003-0715
all versions
Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers
CVE-2003-0528
all versions
Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers
CVE-2003-0525
all versions
The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attac
CVE-2003-0352
all versions
Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers
CVE-2003-0345
all versions
Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service
CVE-2003-0469
all versions
Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial
CVE-2003-0227
all versions
The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Micr
CVE-2003-0112
all versions
Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugg
CVE-2002-1561
all versions
The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled R
CVE-2003-0010
all versions
Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows op
CVE-2003-0003
all versions
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and
CVE-2002-2401
all versions
NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable fil
CVE-2002-2073
all versions
Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote att
CVE-2002-2028
all versions
The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid pas
CVE-2002-1712
all versions
Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/I
CVE-2002-1325
all versions
Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java
CVE-2002-1260
all versions
The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass
CVE-2002-1258
all versions
Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other a
CVE-2002-1257
all versions
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a
CVE-2002-1183
all versions
Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote atta
CVE-2002-1184
all versions
The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in
CVE-2002-0863
all versions
Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plain
CVE-2002-0694
all versions
The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Win
CVE-2002-0693
all versions
Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4
CVE-2002-0862
all versions
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Micros
CVE-2002-0699
all versions
Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Mi
CVE-2002-0724
all versions
Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to c
CVE-2002-0725
all versions
NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to th
5.5MEDIUM
CVE-2002-0421
all versions
IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password cha
CVE-2002-0391
all versions
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC in
9.8CRITICAL
CVE-2002-0366
all versions
Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS)
CVE-2002-0367
all versions
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs
7.8HIGH
CVE-2002-0151
all versions
Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of serv
CVE-2002-0070
all versions
Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary cod
CVE-2002-0053
all versions
Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers
CVE-2002-0018
all versions
In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not
CVE-2001-0879
all versions
Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service.
CVE-2001-0663
all versions
Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remo
CVE-2001-0662
all versions
RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed
CVE-2001-0543
all versions
Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaus
CVE-2001-0509
all versions
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) W
CVE-2001-1452
all versions
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, whi
7.5HIGH
CVE-2000-1200
all versions
Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy po
CVE-2001-1122
all versions
Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by
CVE-2001-1288
all versions
Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt
CVE-2001-0341
all versions
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to exe
CVE-2001-1244
all versions
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting t
CVE-2001-0238
all versions
Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Z
CVE-2001-0373
all versions
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-
CVE-2001-0281
all versions
Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through
CVE-2001-0017
<= 4.0
Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka
CVE-2001-0016
<= 4.0
NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow
CVE-2001-0047
all versions
The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify
CVE-2001-0046
all versions
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify
CVE-2001-0045
all versions
The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by chang
CVE-2001-0006
all versions
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local u
7.1HIGH
CVE-2001-0003
all versions
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer secur
CVE-2000-1149
all versions
Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a l
CVE-2000-1089
all versions
Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buff
CVE-2000-1039
all versions
Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with
CVE-2000-1227
all versions
Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending mul
CVE-2000-0885
all versions
Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Nam
CVE-1999-1579
all versions
The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allo
CVE-2000-0858
all versions
Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of ma
CVE-2000-1079
all versions
Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote a
CVE-2000-0673
all versions
The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of servic
CVE-2000-0663
all versions
The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which
CVE-1999-0585
all versions
A Windows NT administrator account has the default name of Administrator.
CVE-2000-0377
all versions
The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request
CVE-2000-0544
all versions
Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests th
CVE-1999-0590
all versions
A system does not present an appropriate legal message or warning to a user who is accessing it.
CVE-2000-0404
all versions
The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Mast
CVE-2000-0403
all versions
The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large numbe
CVE-2000-0305
all versions
Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of ser
CVE-1999-0980
all versions
Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resour
CVE-2000-0331
all versions
Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of
CVE-2000-0256
all versions
Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that
CVE-2000-1218
all versions
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching par
9.8CRITICAL
CVE-2000-0259
all versions
The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users
CVE-1999-0701
all versions
After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Adm
CVE-2000-0232
all versions
Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed T
CVE-2000-0155
all versions
Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate prog
CVE-2000-0197
all versions
The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the
CVE-2000-0129
all versions
Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by perf
CVE-2000-0089
all versions
The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file wit
CVE-2000-0121
all versions
The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with
CVE-1999-0595
all versions
A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.
CVE-2000-0070
all versions
NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC Port Requ
CVE-1999-1455
<= 4.0
RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a
CVE-1999-1452
all versions
GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the
CVE-1999-1364
all versions
Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) Get
CVE-1999-1363
all versions
Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of
CVE-1999-1362
<= 4.0
Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K function
CVE-1999-1360
all versions
Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in
CVE-1999-1359
all versions
When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce polic
CVE-1999-1358
all versions
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfi
CVE-1999-1317
<= 4.0
Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder
CVE-1999-1316
all versions
Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an
CVE-1999-1294
all versions
Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Man
CVE-1999-1222
all versions
Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the I
CVE-1999-1157
<= 4.0
Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Reques
CVE-1999-1132
all versions
Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing In
CVE-1999-1127
all versions
Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of
7.5HIGH
CVE-1999-1084
all versions
The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan
CVE-1999-0815
<= 4.0
Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion)
CVE-1999-0995
all versions
Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaL
CVE-1999-0994
all versions
Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwor
CVE-1999-0975
all versions
The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a
CVE-1999-0819
all versions
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
CVE-1999-0824
all versions
A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allo
CVE-1999-0987
all versions
Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domai
CVE-2000-0073
all versions
Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control w
CVE-1999-0899
all versions
The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the
CVE-1999-0898
all versions
Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malf
CVE-1999-1234
all versions
LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) S
CVE-1999-0909
all versions
Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options
CVE-1999-0886
all versions
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
CVE-2000-0328
all versions
Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing
CVE-1999-0700
all versions
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
CVE-1999-0224
all versions
Denial of service in Windows NT messenger service through a long username.
CVE-1999-0721
all versions
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
CVE-1999-0728
all versions
A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.
CVE-1999-0918
all versions
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
CVE-1999-0726
all versions
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
CVE-1999-0140
all versions
Denial of service in RAS/PPTP on NT systems.
CVE-1999-1365
all versions
Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as N
CVE-1999-0723
all versions
The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting
CVE-1999-0874
all versions
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC,
CVE-1999-0755
all versions
Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.
CVE-1999-0715
all versions
Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a ma
CVE-1999-0716
all versions
Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.
CVE-1999-0489
all versions
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a varian
CVE-1999-0717
all versions
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
CVE-1999-0444
all versions
Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display fo
CVE-1999-0382
all versions
The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run prog
CVE-1999-1254
all versions
Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, w
CVE-1999-0376
all versions
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.
CVE-1999-0372
all versions
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
CVE-1999-0366
all versions
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with
CVE-1999-0119
all versions
Windows NT 4.0 beta allows users to read and delete shares.
CVE-1999-0391
all versions
The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the r
CVE-1999-0593
all versions
The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a
CVE-1999-0581
all versions
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.
CVE-1999-0579
all versions
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
CVE-1999-0578
all versions
A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.
CVE-1999-0577
all versions
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
CVE-1999-0570
all versions
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.
CVE-1999-0560
all versions
A system-critical Windows NT file or directory has inappropriate permissions.
CVE-1999-0549
all versions
Windows NT automatically logs in an administrator upon rebooting.
CVE-1999-0384
all versions
The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard w
CVE-1999-0285
all versions
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
CVE-1999-0226
all versions
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
CVE-1999-1291
all versions
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections b
CVE-1999-0546
all versions
The Windows NT guest account is enabled.
CVE-1999-0506
all versions
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
CVE-1999-0505
all versions
A Windows NT domain user or administrator account has a guessable password.
CVE-1999-0969
all versions
The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which genera
CVE-1999-0344
all versions
NT users can gain debug-level access on a system process using the Sechole exploit.
CVE-1999-0288
all versions
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination)
CVE-1999-0278
all versions
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
CVE-1999-1361
all versions
Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resourc
CVE-1999-0225
all versions
Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data siz
CVE-1999-0258
all versions
Bonk variation of teardrop IP fragmentation denial of service.
CVE-1999-0256
all versions
Buffer overflow in War FTP allows remote execution of commands.
CVE-1999-1581
all versions
Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote a
CVE-1999-0104
all versions
A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.
CVE-1999-0015
all versions
Teardrop IP denial of service.
CVE-1999-0016
all versions
Land IP denial of service.
CVE-1999-1217
all versions
The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Tro
CVE-1999-1463
<= 4.0
Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending
CVE-1999-0153
all versions
Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
CVE-1999-0074
all versions
Listening TCP ports are sequentially allocated, allowing spoofing attacks.
CVE-1999-0275
all versions
Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.
CVE-1999-0227
all versions
Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.
CVE-1999-1387
all versions
Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as
CVE-1999-0292
all versions
Denial of service through Winpopup using large user names.
CVE-1999-0612
all versions
A version of finger is running that exposes valid user information to any entity on the network.
CVE-1999-0228
all versions
Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.
CVE-1999-0582
all versions
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad lo
CVE-1999-0576
all versions
A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.
CVE-1999-0575
all versions
A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Acces
CVE-1999-0572
all versions
.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.
CVE-1999-0562
all versions
The registry in Windows NT can be accessed remotely by users who are not administrators.
CVE-1999-0535
all versions
A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, o
CVE-1999-0534
all versions
A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create
CVE-1999-0519
all versions
A NETBIOS/SMB share password is the default, null, or missing.
CVE-1999-0511
all versions
IP forwarding is enabled on a machine which is not a router or firewall.
9.1CRITICAL
CVE-1999-0504
all versions
A Windows NT local user or administrator account has a default, null, blank, or missing password.
CVE-1999-0503
all versions
A Windows NT local user or administrator account has a guessable password.
CVE-1999-0499
all versions
NETBIOS share information may be published through SNMP registry keys in NT.
CVE-1999-0496
all versions
A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions
CVE-1999-0274
all versions
Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.
CVE-1999-0249
all versions
Windows NT RSHSVC program allows remote users to execute arbitrary commands.
CVE-1999-0179
all versions
Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.
CVE-1999-0077
all versions
Predictable TCP sequence numbers allow spoofing.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin