Microsoft Windows Nt vulnerabilities
201 known vulnerabilities affecting microsoft/windows_nt.
Total CVEs
201
CISA KEV
2
actively exploited
Public exploits
69
Exploited in wild
5
Severity breakdown
CRITICAL26HIGH73MEDIUM82LOW20
Vulnerabilities
Page 2 of 11
CVE-2006-0988P3HIGHCVSS 7.8PoCv4.02006-03-03
CVE-2006-0988 [HIGH] CVE-2006-0988: The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the
The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed sou
nvd
CVE-2003-0003P3HIGHCVSS 7.5PoCv4.02003-02-07
CVE-2003-0003 [HIGH] CVE-2003-0003: Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Ser
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
nvd
CVE-2003-0910P3HIGHCVSS 7.2PoCv4.02004-06-01
CVE-2003-0910 [HIGH] CVE-2003-0910: The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Wi
The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.
nvd
CVE-2001-0341P3HIGHCVSS 7.5PoCv4.02001-07-21
CVE-2001-0341 [HIGH] CVE-2001-0341: Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.
nvd
CVE-2002-1183P3HIGHCVSS 7.5PoCv4.02002-12-11
CVE-2002-1183 [HIGH] CVE-2002-1183: Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital cert
Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).
nvd
CVE-2002-0693P3HIGHCVSS 7.5PoCv4.02002-10-10
CVE-2002-0693 [HIGH] CVE-2002-0693: Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edi
Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.
nvd
CVE-2003-0659P3HIGHCVSS 7.2PoCv4.02003-11-17
CVE-2003-0659 [HIGH] CVE-2003-0659: Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to
Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.
nvd
CVE-2004-1305P3MEDIUMCVSS 5.0PoCv4.02004-12-23
CVE-2004-1305 [MEDIUM] CVE-2004-1305: The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP thr
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhau
nvd
CVE-2003-0469P3HIGHCVSS 7.5PoCv4.02003-08-07
CVE-2003-0469 [HIGH] CVE-2003-0469: Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remot
Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using a long "align" argument in an HR tag.
nvd
CVE-1999-0886P3CRITICALCVSS 9.0PoCv4.01999-09-17
CVE-1999-0886 [CRITICAL] CWE-16 CVE-1999-0886: The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
nvd
CVE-1999-0278P4MEDIUMCVSS 5.0PoCv4.01998-06-01
CVE-1999-0278 [MEDIUM] CVE-1999-0278: In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
nvd
CVE-2000-0305P3HIGHCVSS 7.8PoCv4.02000-05-19
CVE-2000-0305 [HIGH] CWE-399 CVE-2000-0305: Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote att
Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.
nvd
CVE-2002-0724P3HIGHCVSS 7.5PoCv4.02002-09-24
CVE-2002-0724 [HIGH] CVE-2002-0724: Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Wi
Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".
nvd
CVE-2002-0391P3CRITICALCVSS 9.8v4.02002-08-12
CVE-2002-0391 [CRITICAL] CWE-190 CVE-2002-0391: Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
nvd
CVE-2004-0201P3CRITICALCVSS 10.0v4.02004-08-06
CVE-2004-0201 [CRITICAL] CVE-2004-0201: Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, M
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
nvd
CVE-2004-1306P3MEDIUMCVSS 5.1PoCv4.02004-12-31
CVE-2004-1306 [MEDIUM] CVE-2004-1306: Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP throu
Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.
nvd
CVE-2005-0050P3CRITICALCVSS 10.0v4.02005-05-02
CVE-2005-0050 [CRITICAL] CWE-20 CVE-2005-0050: The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does
The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."
nvd
CVE-2003-0227P4MEDIUMCVSS 5.0PoCv4.02003-06-09
CVE-2003-0227 [MEDIUM] CWE-119 CVE-2003-0227: The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft
The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.
nvd
CVE-1999-0918P4HIGHCVSS 7.8PoCv4.01999-07-03
CVE-1999-0918 [HIGH] CWE-20 CVE-1999-0918: Denial of service in various Windows systems via malformed, fragmented IGMP packets.
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
nvd
CVE-2006-0034P3HIGHCVSS 7.5v4.02006-05-10
CVE-2006-0034 [HIGH] CWE-119 CVE-2006-0034: Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Mic
Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllo
nvd