cbcvebase.

Microsoft Windows Nt vulnerabilities

201 known vulnerabilities affecting microsoft/windows_nt.

Total CVEs
201
CISA KEV
2
actively exploited
Public exploits
69
Exploited in wild
5
Severity breakdown
CRITICAL26HIGH73MEDIUM82LOW20

Vulnerabilities

Page 9 of 11
CVE-1999-1234P4MEDIUMCVSS 5.0v4.01999-10-26
CVE-1999-1234 [MEDIUM] CVE-1999-1234: LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL po LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.
nvd
CVE-2003-0112P4MEDIUMCVSS 4.6v4.02003-05-12
CVE-2003-0112 [MEDIUM] CVE-2003-0112: Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error mes Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.
nvd
CVE-2000-1227P4MEDIUMCVSS 5.0v4.02000-12-31
CVE-2000-1227 [MEDIUM] CVE-2000-1227: Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailab Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.
nvd
CVE-1999-0496P4HIGHCVSS 7.2v4.01997-01-01
CVE-1999-0496 [HIGH] CWE-264 CVE-1999-0496: A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regard A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.
nvd
CVE-2002-0699P4MEDIUMCVSS 5.0v4.02002-10-04
CVE-2002-0699 [MEDIUM] CVE-2002-0699: Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.
nvd
CVE-1999-1361P4MEDIUMCVSS 6.4v3.5.1v4.01998-05-09
CVE-1999-1361 [MEDIUM] CVE-1999-1361: Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to caus Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages.
nvd
CVE-2007-1973P4MEDIUMCVSS 6.9v4.02007-04-11
CVE-2007-1973 [MEDIUM] CVE-2007-1973: Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 al Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via the temporary \Device\PhysicalMemory section handle, a related issue to CVE-2007-1206.
nvd
CVE-1999-0179P4MEDIUMCVSS 5.0v3.5.11997-01-01
CVE-1999-0179 [MEDIUM] CWE-17 CVE-1999-0179: Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share. Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.
nvd
CVE-1999-0104P4MEDIUMCVSS 5.0v4.01997-12-16
CVE-1999-0104 [MEDIUM] CVE-1999-0104: A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2. A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.
nvd
CVE-2003-0525P4MEDIUMCVSS 5.0v4.02003-08-27
CVE-2003-0525 [MEDIUM] CVE-2003-0525: The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.
nvd
CVE-2000-0331P4MEDIUMCVSS 5.0v4.02000-04-20
CVE-2000-0331 [MEDIUM] CVE-2000-0331: Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a lo Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.
nvd
CVE-1999-0969P4MEDIUMCVSS 5.0v4.01998-09-29
CVE-1999-0969 [MEDIUM] CVE-1999-0969: The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malf The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.
nvd
CVE-1999-0701P4HIGHCVSS 7.2v4.02000-04-11
CVE-1999-0701 [HIGH] CWE-16 CVE-1999-0701: After an unattended installation of Windows NT 4.0, an installation file could include sensitive inf After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.
nvd
CVE-2001-0046P4MEDIUMCVSS 4.6v4.02001-02-16
CVE-2001-0046 [MEDIUM] CVE-2001-0046: The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attacke The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.
nvd
CVE-1999-0274P4MEDIUMCVSS 5.0v4.01997-01-01
CVE-1999-0274 [MEDIUM] CVE-1999-0274: Denial of service in Windows NT DNS servers through malicious packet which contains a response to a Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.
nvd
CVE-1999-0227P4MEDIUMCVSS 5.0v4.01997-06-01
CVE-1999-0227 [MEDIUM] CWE-264 CVE-1999-0227: Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service. Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.
nvd
CVE-1999-0228P4MEDIUMCVSS 5.0v4.01997-02-07
CVE-1999-0228 [MEDIUM] CVE-1999-0228: Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT. Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.
nvd
CVE-2000-0663P4MEDIUMCVSS 4.6v4.02000-07-25
CVE-2000-0663 [MEDIUM] CVE-2000-0663: The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 us The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative Shell Path" vulnerability.
nvd
CVE-2002-1184P4MEDIUMCVSS 4.6v4.02002-11-12
CVE-2002-1184 [MEDIUM] CVE-2002-1184: The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.
nvd
CVE-1999-0292P4MEDIUMCVSS 5.0v4.01997-04-01
CVE-1999-0292 [MEDIUM] CVE-1999-0292: Denial of service through Winpopup using large user names. Denial of service through Winpopup using large user names.
nvd
Microsoft Windows Nt vulnerabilities | cvebase