cbcvebase.

Microsoft Windows Nt vulnerabilities

201 known vulnerabilities affecting microsoft/windows_nt.

Total CVEs
201
CISA KEV
2
actively exploited
Public exploits
69
Exploited in wild
5
Severity breakdown
CRITICAL26HIGH73MEDIUM82LOW20

Vulnerabilities

Page 6 of 11
CVE-2005-2150P4MEDIUMCVSS 5.0v4.02005-07-11
CVE-2005-2150 [MEDIUM] CVE-2005-2150: Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sess Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.
nvd
CVE-2000-0232P4LOWCVSS 2.1PoCv4.02000-03-30
CVE-2000-0232 [LOW] CVE-2000-0232: Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denia Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request.
nvd
CVE-2006-1184P4MEDIUMCVSS 5.0v4.02006-05-10
CVE-2006-1184 [MEDIUM] CVE-2006-1184: Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOT
nvd
CVE-2000-1200P4MEDIUMCVSS 5.0v4.02001-08-31
CVE-2000-1200 [MEDIUM] CVE-2000-1200: Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with th Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.
nvd
CVE-2003-1048P4HIGHCVSS 7.8v4.02004-07-27
CVE-2003-1048 [HIGH] CWE-415 CVE-2003-1048: Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.
nvd
CVE-2002-0694P4HIGHCVSS 7.5v4.02002-10-10
CVE-2002-0694 [HIGH] CVE-2002-0694: The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4. The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a mali
nvd
CVE-1999-0995P4HIGHCVSS 7.8v4.01999-12-16
CVE-1999-0995 [HIGH] CWE-20 CVE-1999-0995: Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via m Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request."
nvd
CVE-2000-1039P4MEDIUMCVSS 5.0v4.02001-01-09
CVE-2000-1039 [MEDIUM] CVE-2000-1039: Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service b Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities. NOTE: this candidate may change significantly as the security com
nvd
CVE-2000-0885P4HIGHCVSS 7.5v4.02000-12-19
CVE-2000-0885 [HIGH] CVE-2000-0885: Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary c Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candid
nvd
CVE-2000-1079P4HIGHCVSS 7.5v4.02000-08-29
CVE-2000-1079 [HIGH] CVE-2000-1079: Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 9 Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.
nvd
CVE-1999-0909P4HIGHCVSS 7.5v4.01999-09-20
CVE-1999-0909 [HIGH] CWE-264 CVE-1999-0909: Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a ma Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.
nvd
CVE-1999-1127P4HIGHCVSS 7.5v4.01999-12-31
CVE-1999-1127 [HIGH] CWE-772 CVE-1999-1127: Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote a Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability.
nvd
CVE-2002-0863P4MEDIUMCVSS 5.0v4.02002-10-11
CVE-2002-0863 [MEDIUM] CVE-2002-0863: Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."
nvd
CVE-2002-0421P4MEDIUMCVSS 5.0v4.02002-08-12
CVE-2002-0421 [MEDIUM] CVE-2002-0421: IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by dire IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.
nvd
CVE-1999-0119P4CRITICALCVSS 10.0v4.01999-01-19
CVE-1999-0119 [CRITICAL] CVE-1999-0119: Windows NT 4.0 beta allows users to read and delete shares. Windows NT 4.0 beta allows users to read and delete shares.
nvd
CVE-2001-0047P4HIGHCVSS 7.5v4.0vterminal_server2001-02-16
CVE-2001-0047 [HIGH] CVE-2001-0047: The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows loc The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities.
nvd
CVE-2006-1591P4MEDIUMCVSS 5.1v4.02006-04-03
CVE-2006-1591 [MEDIUM] CVE-2006-1591: Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to execute arbitrary code via crafted embedded image data in a .hlp file.
nvd
CVE-2003-0661P4MEDIUMCVSS 5.0v4.02003-10-20
CVE-2003-0661 [MEDIUM] CVE-2003-0661: The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include r The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.
nvd
CVE-1999-0391P4HIGHCVSS 7.5v3.5.1v4.01999-01-05
CVE-1999-0391 [HIGH] CVE-1999-0391: The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowi The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.
nvd
CVE-1999-1455P4HIGHCVSS 7.5≤ 4.01999-12-31
CVE-1999-1455 [HIGH] CVE-1999-1455: RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specif RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host.
nvd
Microsoft Windows Nt vulnerabilities | cvebase