cbcvebase.

Microsoft Windows Nt vulnerabilities

201 known vulnerabilities affecting microsoft/windows_nt.

Total CVEs
201
CISA KEV
2
actively exploited
Public exploits
69
Exploited in wild
5
Severity breakdown
CRITICAL26HIGH73MEDIUM82LOW20

Vulnerabilities

Page 5 of 11
CVE-2000-1149P3HIGHCVSS 7.5vterminal_server2001-01-09
CVE-2000-1149 [HIGH] CVE-2000-1149: Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to exec Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the "Terminal Server Login Buffer Overflow" vulnerability.
nvd
CVE-2002-1260P3HIGHCVSS 7.5v4.02002-12-23
CVE-2002-1260 [HIGH] CVE-2002-1260: The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier al The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet.
nvd
CVE-2001-0238P3HIGHCVSS 7.5v4.02001-07-02
CVE-2001-0238 [HIGH] CVE-2001-0238: Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.
nvd
CVE-1999-0715P4MEDIUMCVSS 4.6PoCv4.01999-05-20
CVE-1999-0715 [MEDIUM] CVE-1999-0715: Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or caus Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.
nvd
CVE-1999-0489P3CRITICALCVSS 10.0v4.01999-05-17
CVE-1999-0489 [CRITICAL] CVE-1999-0489: MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file uplo MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.
nvd
CVE-2003-0825P3CRITICALCVSS 9.3v4.02004-03-03
CVE-2003-0825 [CRITICAL] CWE-20 CVE-2003-0825: The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows N The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.
nvd
CVE-2001-0045P4CRITICALCVSS 10.0v4.0vterminal_server2001-02-16
CVE-2001-0045 [CRITICAL] CVE-2001-0045: The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execu The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.
nvd
CVE-2001-0006P4HIGHCVSS 7.1PoCv4.02001-02-12
CVE-2001-0006 [HIGH] CWE-732 CVE-2001-0006: The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control per The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.
nvd
CVE-2002-0070P4HIGHCVSS 7.6v4.02002-03-15
CVE-2002-0070 [HIGH] CWE-119 CVE-2002-0070: Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote atta Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.
nvd
CVE-2004-1361P4MEDIUMCVSS 5.0v4.02004-12-23
CVE-2004-1361 [MEDIUM] CVE-2004-1361: Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, a Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.
nvd
CVE-1999-0376P4MEDIUMCVSS 4.6PoCv3.5.1v4.01999-02-20
CVE-1999-0376 [MEDIUM] CVE-1999-0376: Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to refe Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.
nvd
CVE-2000-0121P4LOWCVSS 3.6PoCv4.02000-02-01
CVE-2000-0121 [LOW] CVE-2000-0121: The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creation" vulnerability.
nvd
CVE-1999-0700P4MEDIUMCVSS 6.2PoCv4.01999-07-29
CVE-1999-0700 [MEDIUM] CWE-119 CVE-1999-0700: Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.i Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
nvd
CVE-2003-0807P4MEDIUMCVSS 5.0v4.02004-06-01
CVE-2003-0807 [MEDIUM] CVE-2003-0807: Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.
nvd
CVE-2004-0569P4HIGHCVSS 7.5v4.02004-11-03
CVE-2004-0569 [HIGH] CVE-2004-0569: The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory o The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.
nvd
CVE-1999-1084P4MEDIUMCVSS 4.6PoCv4.01999-12-31
CVE-1999-1084 [MEDIUM] CVE-1999-1084: The "AEDebug" registry key is installed with insecure permissions, which allows local users to modif The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.
nvd
CVE-2001-1122P4LOWCVSS 2.1PoCv4.02001-08-03
CVE-2001-1122 [LOW] CVE-2001-1122: Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of se Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode.
nvd
CVE-1999-0716P4MEDIUMCVSS 4.6PoCv4.01999-05-17
CVE-1999-0716 [MEDIUM] CVE-1999-0716: Buffer overflow in Windows NT 4.0 help file utility via a malformed help file. Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.
nvd
CVE-1999-0975P4MEDIUMCVSS 4.6PoCv4.01999-12-10
CVE-1999-0975 [MEDIUM] CVE-1999-0975: The Windows help system can allow a local user to execute commands as another user by editing a tabl The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.
nvd
CVE-2000-0129P4LOWCVSS 2.1PoCv4.02000-02-04
CVE-2000-0129 [LOW] CVE-2000-0129: Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cau Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.
nvd
Microsoft Windows Nt vulnerabilities | cvebase