cbcvebase.

Microsoft Windows Nt vulnerabilities

201 known vulnerabilities affecting microsoft/windows_nt.

Total CVEs
201
CISA KEV
2
actively exploited
Public exploits
69
Exploited in wild
5
Severity breakdown
CRITICAL26HIGH73MEDIUM82LOW20

Vulnerabilities

Page 7 of 11
CVE-1999-0366P4HIGHCVSS 7.5v4.01999-02-08
CVE-1999-0366 [HIGH] CWE-287 CVE-1999-0366: In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank pa In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.
nvd
CVE-2001-1452P4HIGHCVSS 7.5v4.02001-08-31
CVE-2001-1452 [HIGH] CWE-346 CVE-2001-1452: By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from n By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.
nvd
CVE-1999-0728P4HIGHCVSS 7.8v4.01999-07-06
CVE-1999-0728 [HIGH] CWE-264 CVE-1999-0728: A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control the A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.
nvd
CVE-2000-0328P4MEDIUMCVSS 5.0v4.01999-08-24
CVE-2000-0328 [MEDIUM] CVE-2000-0328: Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.
nvd
CVE-2000-1218P4CRITICALCVSS 9.8v4.02000-04-14
CVE-2000-1218 [CRITICAL] CWE-346 CVE-2000-1218: The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and X The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
nvd
CVE-1999-0590P4CRITICALCVSS 10.0v3.5.1v4.02000-06-01
CVE-1999-0590 [CRITICAL] CVE-1999-0590: A system does not present an appropriate legal message or warning to a user who is accessing it. A system does not present an appropriate legal message or warning to a user who is accessing it.
nvd
CVE-2004-0124P4LOWCVSS 2.6v4.02004-06-01
CVE-2004-0124 [LOW] CVE-2004-0124: The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attacke The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."
nvd
CVE-1999-0721P4HIGHCVSS 7.8v4.01999-07-20
CVE-1999-0721 [HIGH] CWE-20 CVE-1999-0721: Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request. Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
nvd
CVE-1999-0726P4HIGHCVSS 7.8v4.01999-06-30
CVE-1999-0726 [HIGH] CWE-20 CVE-1999-0726: An attacker can conduct a denial of service in Windows NT by executing a program with a malformed fi An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
nvd
CVE-2002-0366P4HIGHCVSS 7.2v4.02002-07-03
CVE-2002-0366 [HIGH] CVE-2002-0366: Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing a Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.
nvd
CVE-2000-0070P4HIGHCVSS 7.2v4.02000-01-12
CVE-2000-0070 [HIGH] CVE-2000-0070: NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileg NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC Port Request."
nvd
CVE-2004-0893P4HIGHCVSS 7.2v4.02005-01-10
CVE-2004-0893 [HIGH] CVE-2004-0893: The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Win The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."
nvd
CVE-1999-1579P4MEDIUMCVSS 5.0v4.02000-12-14
CVE-1999-1579 [MEDIUM] CVE-1999-1579: The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on the target machine.
nvd
CVE-2003-0813P4MEDIUMCVSS 5.1v4.02003-11-17
CVE-2003-0813 [MEDIUM] CVE-2003-0813: A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch instal A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2
nvd
CVE-2004-0208P4HIGHCVSS 7.2v4.02004-11-03
CVE-2004-0208 [HIGH] CVE-2004-0208: The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and W The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.
nvd
CVE-2000-0403P4MEDIUMCVSS 5.0v4.02000-05-25
CVE-2000-0403 [MEDIUM] CVE-2000-0403: The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of se The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the "HostAnnouncement Flooding" or "HostAnnouncement Frame" vulnerability.
nvd
CVE-2001-0017P4MEDIUMCVSS 5.0≤ 4.02001-03-12
CVE-2001-0017 [MEDIUM] CVE-2001-0017: Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service vi Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability.
nvd
CVE-2001-0509P4MEDIUMCVSS 5.0v4.02001-09-20
CVE-2001-0509 [MEDIUM] CWE-20 CVE-2001-0509: Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.
nvd
CVE-2001-0662P4MEDIUMCVSS 5.0v4.02001-10-30
CVE-2001-0662 [MEDIUM] CVE-2001-0662: RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed request.
nvd
CVE-1999-1291P4MEDIUMCVSS 5.0v4.01998-10-05
CVE-1999-1291 [MEDIUM] CVE-1999-1291: TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote at TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.
nvd
Microsoft Windows Nt vulnerabilities | cvebase