cbcvebase.

Microsoft Windows Nt vulnerabilities

201 known vulnerabilities affecting microsoft/windows_nt.

Total CVEs
201
CISA KEV
2
actively exploited
Public exploits
69
Exploited in wild
5
Severity breakdown
CRITICAL26HIGH73MEDIUM82LOW20

Vulnerabilities

Page 1 of 11
CVE-2002-0367P2HIGHCVSS 7.8KEVPoCv4.02002-06-25
CVE-2002-0367 [HIGH] CWE-269 CVE-2002-0367: smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
nvd
CVE-2004-0210P2HIGHCVSS 7.8KEVPoCv4.02004-08-06
CVE-2004-0210 [HIGH] CWE-120 CVE-2004-0210: The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
nvd
CVE-2003-0352P2HIGHCVSS 7.5ExploitedPoCv4.02003-08-18
CVE-2003-0352 [HIGH] CVE-2003-0352: Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Serve Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.
nvd
CVE-2003-0533P2HIGHCVSS 7.5ExploitedPoCv4.02004-06-01
CVE-2003-0533 [HIGH] CVE-2003-0533: Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlev
nvd
CVE-2007-6026P2CRITICALCVSS 9.3ExploitedPoCv4.02007-11-20
CVE-2007-6026 [CRITICAL] CWE-119 CVE-2007-6026: Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.
nvd
CVE-2004-0206P2HIGHCVSS 7.5PoCv4.02004-11-03
CVE-2004-0206 [HIGH] CVE-2004-0206: Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 20 Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.
nvd
CVE-2004-1080P2CRITICALCVSS 10.0PoCv4.02005-01-10
CVE-2004-1080 [CRITICAL] CVE-2004-1080: The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Ser The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."
nvd
CVE-2004-0574P2CRITICALCVSS 10.0PoCv4.02004-11-03
CVE-2004-0574 [CRITICAL] CWE-787 CVE-2004-0574: The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-
nvd
CVE-2006-2379P2CRITICALCVSS 9.3PoCv4.02006-06-13
CVE-2006-2379 [CRITICAL] CWE-119 CVE-2006-2379: Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Ser Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.
nvd
CVE-2005-0045P2HIGHCVSS 7.5PoCv4.02005-05-02
CVE-2005-0045 [HIGH] CVE-2005-0045: The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 respo
nvd
CVE-2003-0719P3HIGHCVSS 7.5PoCv4.02004-06-01
CVE-2003-0719 [HIGH] CVE-2003-0719: Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microso Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.
nvd
CVE-2003-0717P2HIGHCVSS 7.5PoCv4.02003-11-17
CVE-2003-0717 [HIGH] CVE-2003-0717: The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
nvd
CVE-2003-0818P3HIGHCVSS 7.5PoCv4.02004-03-03
CVE-2003-0818 [HIGH] CVE-2003-0818: Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DL Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit stri
nvd
CVE-2004-0567P3HIGHCVSS 7.5PoCv4.02004-12-31
CVE-2004-0567 [HIGH] CVE-2004-0567: The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked b
nvd
CVE-2005-0416P3HIGHCVSS 7.5PoCv4.02005-04-27
CVE-2005-0416 [HIGH] CVE-2005-0416: The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP thr The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to execute arbitrary code via the AnimationHeaderBlock length field, which leads to a stack-based buffer overflow.
nvd
CVE-2004-0212P3CRITICALCVSS 10.0PoCv4.02004-08-06
CVE-2004-0212 [CRITICAL] CVE-2004-0212: Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 o Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.
nvd
CVE-1999-0874P3CRITICALCVSS 10.0PoCv4.01999-06-16
CVE-1999-0874 [CRITICAL] CWE-119 CVE-1999-0874: Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed requ Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
nvd
CVE-2000-1089P3CRITICALCVSS 10.0PoCv4.02001-01-09
CVE-2000-1089 [CRITICAL] CVE-2000-1089: Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, ak Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.
nvd
CVE-2008-5232P3CRITICALCVSS 9.3PoCv4.02008-11-26
CVE-2008-5232 [CRITICAL] CWE-787 CVE-2008-5232: Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control i Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unk
nvd
CVE-2005-1935P3HIGHCVSS 7.5PoCv4.02005-06-13
CVE-2005-1935 [HIGH] CVE-2005-1935: Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) a Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the function to overwrite previously freed memory, as demonstrated using a SPNEGO token with a constructed bit string du
nvd
1 / 11Next →
Microsoft Windows Nt vulnerabilities | cvebase