VendorsMicrosoftwindows_ntany version
Vulnerabilities

Microsoft Windows any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

87CVEs
CVE-1999-0549
Windows NT automatically logs in an administrator upon rebooting.
Published 2000-02-04 · Modified
7.2EPSS 0.018
CVE-2007-3958
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain GIF file, as demonstrated by Art.gif.
Published 2007-07-24 · Modified
7.11 PoCEPSS 0.228
CVE-1999-0723
The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.
Published 2000-01-04 · Modified
7.1EPSS 0.073
CVE-2008-2841
Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI.
Published 2008-06-24 · Modified
6.81 PoCEPSS 0.154
CVE-2007-1912
Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file.
Published 2007-04-10 · Modified
6.81 PoCEPSS 0.115
CVE-2006-7031
Microsoft Internet Explorer 6.0.2900 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a table element with a CSS attribute that sets the position, which triggers an "unhandled exception" in mshtml.dll.
Published 2007-02-23 · Modified
6.51 PoCEPSS 0.183
CVE-2007-1727
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.
Published 2007-03-28 · Modified
6.5EPSS 0.015
CVE-1999-0074
Listening TCP ports are sequentially allocated, allowing spoofing attacks.
Published 1999-09-29 · Modified
6.4EPSS 0.083
CVE-2008-2674
Unspecified vulnerability in the Interstage Management Console, as used in Fujitsu Interstage Application Server 6.0 through 9.0.0A, Apworks Modelers-J 6.0 through 7.0, and Studio 8.0.1 and 9.0.0, allows remote attackers to read or delete arbitrary files via unspecified vectors.
Published 2008-06-12 · Modified
6.4EPSS 0.014
CVE-1999-0700
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
Published 2000-01-04 · Modified
6.21 PoCEPSS 0.029
CVE-2004-1049
Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."
Published 2005-01-19 · Modified
5.1EPSS 0.306
CVE-1999-0153
Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
Published 1999-09-29 · Modified
5.04 PoCEPSS 0.211
CVE-2011-5279
CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a \n (newline) character in an HTTP header.
Published 2014-04-23 · Modified
5.0EPSS 0.192
CVE-1999-0815
Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.
Published 2002-03-09 · Modified
5.0EPSS 0.178
CVE-2001-0017
Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability.
Published 2001-05-07 · Modified
5.0EPSS 0.173
CVE-2006-7030
Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required arguments, which triggers a null pointer dereference in mshtml.dll.
Published 2007-02-23 · Modified
5.0EPSS 0.173
CVE-1999-1463
Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.
Published 2001-09-12 · Modified
5.0EPSS 0.166
CVE-1999-0444
Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.
Published 2000-02-04 · Modified
5.0EPSS 0.165
CVE-1999-0755
Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.
Published 2000-01-04 · Modified
5.01 PoCEPSS 0.150
CVE-1999-0140
Denial of service in RAS/PPTP on NT systems.
Published 2000-02-04 · Modified
5.01 PoCEPSS 0.136
CVE-1999-1157
Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.
Published 2002-03-09 · Modified
5.0EPSS 0.133
CVE-1999-1254
Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.
Published 2001-09-12 · Modified
5.0EPSS 0.133
CVE-2001-0003
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
Published 2001-05-07 · Modified
5.0EPSS 0.074
CVE-2001-0879
Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service.
Published 2002-03-09 · Modified
5.0EPSS 0.074
CVE-1999-0582
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.
Published 2000-02-04 · Modified
5.0EPSS 0.063
CVE-2003-1469
The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.
Published 2007-10-24 · Modified
5.01 PoCEPSS 0.062
CVE-1999-0275
Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.
Published 2000-01-04 · Modified
5.0EPSS 0.060
CVE-1999-0258
Bonk variation of teardrop IP fragmentation denial of service.
Published 2000-02-04 · Modified
5.0EPSS 0.060
CVE-2007-6334
Ingres 2.5 and 2.6 on Windows, as used in multiple CA products and possibly other products, assigns the privileges and identity of users to be the same as the first user, which allows remote attackers to gain privileges.
Published 2007-12-20 · Modified
5.0EPSS 0.018
CVE-2002-2413
WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8.3 file name.
Published 2007-11-01 · Modified
5.0EPSS 0.012
CVE-1999-0593
The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.
Published 2000-02-04 · Modified
4.9EPSS 0.022
CVE-1999-0715
Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.
Published 2000-01-04 · Modified
4.61 PoCEPSS 0.031
CVE-1999-0716
Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.
Published 2000-01-04 · Modified
4.61 PoCEPSS 0.031
CVE-1999-1217
The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.
Published 2004-09-01 · Modified
4.6EPSS 0.022
CVE-1999-1317
Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.
Published 2002-03-09 · Modified
4.6EPSS 0.018
CVE-1999-0546
The Windows NT guest account is enabled.
Published 2000-02-04 · Modified
4.6EPSS 0.017
CVE-1999-0578
A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.
Published 2000-02-04 · Modified
4.6EPSS 0.015
CVE-1999-0534
A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input.
Published 2000-02-04 · Modified
4.6EPSS 0.015
CVE-1999-1358
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.
Published 2002-03-09 · Modified
4.6EPSS 0.014
CVE-1999-0384
The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.
Published 1999-09-29 · Modified
4.6EPSS 0.012
← Prev2 / 3Next →