cbcvebase.

Microsoft Windows Nt vulnerabilities

201 known vulnerabilities affecting microsoft/windows_nt.

Total CVEs
201
CISA KEV
2
actively exploited
Public exploits
69
Exploited in wild
5
Severity breakdown
CRITICAL26HIGH73MEDIUM82LOW20

Vulnerabilities

Page 4 of 11
CVE-2002-1712P4MEDIUMCVSS 5.0PoCv4.02002-12-31
CVE-2002-1712 [MEDIUM] CVE-2002-1712: Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.
nvd
CVE-2001-0663P4MEDIUMCVSS 5.0PoCv4.02001-12-06
CVE-2001-0663 [MEDIUM] CVE-2001-0663: Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.
nvd
CVE-1999-0819P4MEDIUMCVSS 5.0PoCv4.01999-12-01
CVE-1999-0819 [MEDIUM] CVE-1999-0819: NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it. NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
nvd
CVE-2000-0073P4MEDIUMCVSS 5.0PoCv4.01999-11-17
CVE-2000-0073 [MEDIUM] CVE-2000-0073: Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of ser Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.
nvd
CVE-1999-0382P4HIGHCVSS 7.2PoCv3.5.1v4.01999-03-12
CVE-1999-0382 [HIGH] CVE-1999-0382: The screen saver in Windows NT does not verify that its security context has been changed properly, The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.
nvd
CVE-2003-0345P3HIGHCVSS 7.5v4.02003-08-18
CVE-2003-0345 [HIGH] CVE-2003-0345: Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.
nvd
CVE-1999-0288P4MEDIUMCVSS 5.0PoCv4.01998-08-01
CVE-1999-0288 [MEDIUM] CVE-1999-0288: The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.
nvd
CVE-2002-0053P3HIGHCVSS 7.5v4.02002-03-08
CVE-2002-0053 [HIGH] CVE-2002-0053: Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windo Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. NOTE: this candidate may be split or merged with other candidates. This and other PROTOS-related candidates, especially CVE-2002-0012 and CVE-
nvd
CVE-1999-0980P4MEDIUMCVSS 5.0PoCv4.02000-05-16
CVE-1999-0980 [MEDIUM] CVE-1999-0980: Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request.
nvd
CVE-2002-1257P3CRITICALCVSS 10.0v4.02002-12-23
CVE-2002-1257 [CRITICAL] CVE-2002-1257: Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.
nvd
CVE-2000-0377P4MEDIUMCVSS 5.0PoCv4.02000-06-08
CVE-2000-0377 [MEDIUM] CVE-2000-0377: The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of s The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability.
nvd
CVE-2003-0010P3HIGHCVSS 7.5v4.02003-03-24
CVE-2003-0010 [HIGH] CVE-2003-0010: Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScr Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.
nvd
CVE-2000-0155P4HIGHCVSS 7.2PoCv4.02000-02-18
CVE-2000-0155 [HIGH] CWE-94 CVE-2000-0155: Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attacker Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.
nvd
CVE-2003-0660P3HIGHCVSS 7.5v4.02003-11-17
CVE-2003-0660 [HIGH] CVE-2003-0660: The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers to execute arbitrary code without user approval.
nvd
CVE-1999-0224P4MEDIUMCVSS 5.0PoCv4.01999-07-23
CVE-1999-0224 [MEDIUM] CVE-1999-0224: Denial of service in Windows NT messenger service through a long username. Denial of service in Windows NT messenger service through a long username.
nvd
CVE-2005-4717P4MEDIUMCVSS 5.0PoCv4.02005-12-31
CVE-2005-4717 [MEDIUM] CVE-2005-4717: Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contain
nvd
CVE-2004-0118P3HIGHCVSS 7.2v4.02004-06-01
CVE-2004-0118 [HIGH] CVE-2004-0118: The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does no The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.
nvd
CVE-2004-0899P4MEDIUMCVSS 5.0v4.02005-01-10
CVE-2004-0899 [MEDIUM] CVE-2004-0899: The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP l The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."
nvd
CVE-2002-2073P4MEDIUMCVSS 4.3PoCv4.02002-12-31
CVE-2002-2073 [MEDIUM] CVE-2002-2073: Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Wi Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp.
nvd
CVE-2004-0123P3HIGHCVSS 7.5v4.02004-06-01
CVE-2004-0123 [HIGH] CWE-119 CVE-2004-0123: Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
nvd
Microsoft Windows Nt vulnerabilities | cvebase