VendorsMicrosoftwindows_ntany version
Vulnerabilities

Microsoft Windows any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

87CVEs
CVE-1999-0874
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
Published 2000-06-02 · Modified
10.05 PoCEPSS 0.747
CVE-2007-1070
Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1) CMON_NetTestConnection, (2) CMON_ActiveUpdate, and (3) CMON_ActiveRollback functions in (a) StCommon.dll, and (4) ENG_SetRealTimeScanConfigInfo and (5) ENG_SendEMail functions in (b) eng50.dll.
Published 2007-02-21 · Modified
10.02 PoCEPSS 0.730
CVE-2002-0018
In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.
Published 2002-06-25 · Modified
10.0EPSS 0.164
CVE-1999-0581
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.
Published 2000-02-04 · Modified
10.0EPSS 0.067
CVE-1999-0285
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
Published 2000-02-04 · Modified
10.0EPSS 0.067
CVE-1999-0579
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
Published 2000-02-04 · Modified
10.0EPSS 0.062
CVE-1999-0577
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
Published 2000-02-04 · Modified
10.0EPSS 0.062
CVE-1999-0535
A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.
Published 2000-02-04 · Modified
10.0EPSS 0.061
CVE-1999-0570
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.
Published 2000-02-04 · Modified
10.0EPSS 0.061
CVE-1999-0226
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
Published 2000-02-04 · Modified
10.0EPSS 0.059
CVE-1999-0560
A system-critical Windows NT file or directory has inappropriate permissions.
Published 2000-02-04 · Modified
10.0EPSS 0.059
CVE-1999-0987
Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.
Published 2000-01-04 · Modified
10.0EPSS 0.049
CVE-2003-1357
ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.
Published 2007-10-14 · Modified
10.0EPSS 0.022
CVE-2020-7485
**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier could cause improper access to the TriStation host machine. This was addressed in TriStation version v4.9.1 and v4.10.1 released on May 30, 2013.1
Published 2020-04-15 · Modified
9.8EPSS 0.019
CVE-2008-2427
Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file.
Published 2008-06-24 · Modified
9.31 PoCEPSS 0.161
CVE-2008-2430
Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player 0.8.6h on Windows allows remote attackers to execute arbitrary code via a large fmt chunk in a WAV file.
Published 2008-07-07 · Modified
9.3EPSS 0.059
CVE-1999-0572
.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.
Published 2000-02-04 · Modified
9.3EPSS 0.052
CVE-2008-2821
Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345.
Published 2008-06-23 · Modified
9.31 PoCEPSS 0.025
CVE-1999-0511
IP forwarding is enabled on a machine which is not a router or firewall.
Published 2000-02-04 · Modified
9.1EPSS 0.070
CVE-1999-0726
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
Published 2000-01-04 · Modified
7.8EPSS 0.085
CVE-1999-0721
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
Published 2000-01-04 · Modified
7.8EPSS 0.085
CVE-2007-6423
Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue
Published 2008-01-12 · Modified
7.8EPSS 0.039
CVE-1999-0256
Buffer overflow in War FTP allows remote execution of commands.
Published 1999-09-29 · Modified
7.52 PoCEPSS 0.729
CVE-1999-0504
A Windows NT local user or administrator account has a default, null, blank, or missing password.
Published 2000-02-04 · Modified
7.51 PoCEPSS 0.643
CVE-1999-0562
The registry in Windows NT can be accessed remotely by users who are not administrators.
Published 2000-02-04 · Modified
7.51 PoCEPSS 0.101
CVE-1999-0519
A NETBIOS/SMB share password is the default, null, or missing.
Published 2000-02-04 · Modified
7.5EPSS 0.056
CVE-1999-0575
A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking.
Published 2000-02-04 · Modified
7.5EPSS 0.052
CVE-1999-0576
A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.
Published 2000-02-04 · Modified
7.5EPSS 0.049
CVE-1999-0499
NETBIOS share information may be published through SNMP registry keys in NT.
Published 2000-02-04 · Modified
7.5EPSS 0.048
CVE-1999-1359
When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies.
Published 2002-03-09 · Modified
7.5EPSS 0.039
CVE-1999-1455
RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host.
Published 2002-03-09 · Modified
7.5EPSS 0.039
CVE-2020-7484
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of service attack if the user is not following documented guidelines pertaining to dedicated TriStation connection and key-switch protection. This vulnerability was discovered and remediated in versions v4.9.1 and v4.10.1 on May 30, 2013. This feature is not present in version v4.9.1 and v4.10.1 through current. Therefore, the vulnerability is not present in these versions.
Published 2020-04-15 · Modified
7.5EPSS 0.013
CVE-2020-7483
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled. This vulnerability was discovered in and remediated in versions v4.9.1 and v4.10.1 on May 30, 2013. The 'password' feature is an additional optional check performed by TS1131 that it is connected to a specific controller. This data is sent as clear text and is visible on the network. This feature is not present in TriStation 1131 versions v4.9.1 and v4.10.1 through current. Therefore, the vulnerability is not present in these versions.
Published 2020-04-15 · Modified
7.5EPSS 0.009
CVE-1999-0506
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
Published 2000-02-04 · Modified
7.2EPSS 0.172
CVE-1999-0249
Windows NT RSHSVC program allows remote users to execute arbitrary commands.
Published 2000-02-04 · Modified
7.2EPSS 0.072
CVE-2001-0281
Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.
Published 2001-04-04 · Modified
7.2EPSS 0.048
CVE-1999-1365
Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default.
Published 2004-09-01 · Modified
7.2EPSS 0.028
CVE-2001-0016
NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access.
Published 2001-05-07 · Modified
7.2EPSS 0.021
CVE-1999-0503
A Windows NT local user or administrator account has a guessable password.
Published 2000-02-04 · Modified
7.2EPSS 0.018
CVE-1999-0505
A Windows NT domain user or administrator account has a guessable password.
Published 2000-02-04 · Modified
7.2EPSS 0.018
1 / 3Next →