Microsoft Windows Nt vulnerabilities
201 known vulnerabilities affecting microsoft/windows_nt.
Total CVEs
201
CISA KEV
2
actively exploited
Public exploits
69
Exploited in wild
5
Severity breakdown
CRITICAL26HIGH73MEDIUM82LOW20
Vulnerabilities
Page 3 of 11
CVE-2003-0528P3CRITICALCVSS 10.0v4.02003-09-17
CVE-2003-0528 [CRITICAL] CVE-2003-0528: Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS S
Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.
nvd
CVE-2004-0900P3CRITICALCVSS 10.0v4.02005-01-10
CVE-2004-0900 [CRITICAL] CVE-2004-0900: The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not pro
The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP Request Vulnerability."
nvd
CVE-2006-0010P3CRITICALCVSS 9.3v3.5.1v4.02006-01-10
CVE-2006-0010 [CRITICAL] CWE-119 CVE-2006-0010: Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server
Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.
nvd
CVE-2004-0568P3CRITICALCVSS 10.0v4.02005-01-10
CVE-2004-0568 [CRITICAL] CVE-2004-0568: HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does
HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer
nvd
CVE-2000-0256P4HIGHCVSS 7.5PoCv4.02000-04-19
CVE-2000-0256 [HIGH] CVE-2000-0256: Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a us
Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability.
nvd
CVE-2004-0901P3CRITICALCVSS 10.0v4.02005-01-10
CVE-2004-0901 [CRITICAL] CVE-2004-0901: Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly valid
Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.
nvd
CVE-2004-0571P3CRITICALCVSS 10.0v4.02005-01-10
CVE-2004-0571 [CRITICAL] CVE-2004-0571: Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allo
Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.
nvd
CVE-2003-0715P3CRITICALCVSS 10.0v4.02003-09-17
CVE-2003-0715 [CRITICAL] CVE-2003-0715: Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS S
Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.
nvd
CVE-2005-1184P4MEDIUMCVSS 5.0PoCv4.02005-05-02
CVE-2005-1184 [MEDIUM] CVE-2005-1184: The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service
The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the correct sequence number but the wrong Acknowledgement number, which generates a large number of "keep alive" packets. NOTE: some followups indicate that this issue could not be replicated.
nvd
CVE-2003-0711P3HIGHCVSS 7.5v4.02003-11-17
CVE-2003-0711 [HIGH] CVE-2003-0711: Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Window
Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.
nvd
CVE-2000-0673P4MEDIUMCVSS 5.0PoCv4.0vterminal_server2000-07-27
CVE-2000-0673 [MEDIUM] CVE-2000-0673: The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attacke
The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability.
nvd
CVE-2002-1561P4MEDIUMCVSS 5.0PoCv4.02003-04-02
CVE-2002-1561 [MEDIUM] CVE-2002-1561: The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a
The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.
nvd
CVE-2001-1244P4MEDIUMCVSS 5.0PoCv4.02001-07-07
CVE-2001-1244 [MEDIUM] CVE-2001-1244: Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth an
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.
nvd
CVE-2005-2827P4HIGHCVSS 7.2PoCv4.02005-12-14
CVE-2005-2827 [HIGH] CVE-2005-2827: The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local
The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow via steps in which a terminating thread causes Asynchronous Procedure Call (APC) entries to free the wrong data, aka the "Windows Kernel Vulnerability."
nvd
CVE-2003-0806P3HIGHCVSS 7.5v4.02004-06-01
CVE-2003-0806 [HIGH] CVE-2003-0806: Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 t
Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.
nvd
CVE-2003-0906P3HIGHCVSS 7.6v4.02004-06-01
CVE-2003-0906 [HIGH] CVE-2003-0906: Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image
Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.
nvd
CVE-2002-0862P4MEDIUMCVSS 6.8PoCv4.02002-10-04
CVE-2002-0862 [MEDIUM] CWE-295 CVE-2002-0862: The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs w
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, whic
nvd
CVE-1999-0755P4MEDIUMCVSS 5.0PoCv4.01999-05-27
CVE-1999-0755 [MEDIUM] CWE-255 CVE-1999-0755: Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save
Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.
nvd
CVE-2003-1407P4HIGHCVSS 7.2PoCv4.02003-12-31
CVE-2003-1407 [HIGH] CWE-119 CVE-2003-1407: Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a l
Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the cd command.
nvd
CVE-1999-0899P4HIGHCVSS 7.2PoCv4.01999-11-04
CVE-1999-0899 [HIGH] CWE-264 CVE-1999-0899: The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropri
The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.
nvd