VendorsMicrosoftwindows_ntall versions
Vulnerabilities

Microsoft Windows

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

286CVEs
CVE-2000-0544
Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.
Published 2000-07-12 · Modified
5.0EPSS 0.178
CVE-2001-0017
Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability.
Published 2001-05-07 · Modified
5.0EPSS 0.173
CVE-2006-7030
Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required arguments, which triggers a null pointer dereference in mshtml.dll.
Published 2007-02-23 · Modified
5.0EPSS 0.173
CVE-2001-0509
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.
Published 2001-08-29 · Modified
5.0EPSS 0.170
CVE-1999-0224
Denial of service in Windows NT messenger service through a long username.
Published 1999-09-29 · Modified
5.01 PoCEPSS 0.168
CVE-1999-1463
Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.
Published 2001-09-12 · Modified
5.0EPSS 0.166
CVE-1999-0444
Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.
Published 2000-02-04 · Modified
5.0EPSS 0.165
CVE-2005-4717
Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contains a malformed IMG tag, as demonstrated by IEcrash.htm and IEcrash.rar.
Published 2006-02-15 · Modified
5.01 PoCEPSS 0.163
CVE-2002-1258
Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.
Published 2002-12-17 · Modified
5.0EPSS 0.153
CVE-1999-0755
Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.
Published 2000-01-04 · Modified
5.01 PoCEPSS 0.150
CVE-1999-0819
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
Published 2000-06-02 · Modified
5.01 PoCEPSS 0.148
CVE-2002-1325
Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."
Published 2004-09-01 · Modified
5.0EPSS 0.139
CVE-1999-0140
Denial of service in RAS/PPTP on NT systems.
Published 2000-02-04 · Modified
5.01 PoCEPSS 0.136
CVE-1999-1234
LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.
Published 2001-09-12 · Modified
5.0EPSS 0.135
CVE-1999-1291
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.
Published 2001-09-12 · Modified
5.0EPSS 0.133
CVE-1999-1157
Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.
Published 2002-03-09 · Modified
5.0EPSS 0.133
CVE-1999-1254
Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.
Published 2001-09-12 · Modified
5.0EPSS 0.133
CVE-1999-0969
The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.
Published 2000-01-04 · Modified
5.0EPSS 0.133
CVE-2000-1227
Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.
Published 2005-06-28 · Modified
5.0EPSS 0.130
CVE-1999-0104
A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.
Published 2000-02-04 · Modified
5.0EPSS 0.093
CVE-2003-0525
The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.
Published 2003-07-25 · Modified
5.0EPSS 0.077
CVE-2007-2186
Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
Published 2007-04-24 · Modified
5.01 PoCEPSS 0.076
CVE-2000-0331
Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.
Published 2000-07-12 · Modified
5.0EPSS 0.075
CVE-2001-0003
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
Published 2001-05-07 · Modified
5.0EPSS 0.074
CVE-2001-0879
Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service.
Published 2002-03-09 · Modified
5.0EPSS 0.074
CVE-1999-0994
Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.
Published 2000-01-18 · Modified
5.0EPSS 0.071
CVE-2002-0699
Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.
Published 2002-08-31 · Modified
5.0EPSS 0.065
CVE-1999-0582
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.
Published 2000-02-04 · Modified
5.0EPSS 0.063
CVE-2003-1469
The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.
Published 2007-10-24 · Modified
5.01 PoCEPSS 0.062
CVE-1999-0275
Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.
Published 2000-01-04 · Modified
5.0EPSS 0.060
CVE-1999-0258
Bonk variation of teardrop IP fragmentation denial of service.
Published 2000-02-04 · Modified
5.0EPSS 0.060
CVE-1999-0292
Denial of service through Winpopup using large user names.
Published 1999-09-29 · Modified
5.0EPSS 0.060
CVE-1999-0179
Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.
Published 1999-09-29 · Modified
5.0EPSS 0.060
CVE-1999-0274
Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.
Published 1999-09-29 · Modified
5.0EPSS 0.059
CVE-1999-1222
Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.
Published 2002-03-09 · Modified
5.0EPSS 0.050
CVE-1999-0227
Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.
Published 1999-09-29 · Modified
5.0EPSS 0.050
CVE-1999-0228
Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.
Published 1999-09-29 · Modified
5.0EPSS 0.050
CVE-2007-6334
Ingres 2.5 and 2.6 on Windows, as used in multiple CA products and possibly other products, assigns the privileges and identity of users to be the same as the first user, which allows remote attackers to gain privileges.
Published 2007-12-20 · Modified
5.0EPSS 0.018
CVE-2006-7039
The IMAP4 service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (crash) via a message with a long subject field.
Published 2007-02-23 · Modified
5.0EPSS 0.015
CVE-2002-2413
WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8.3 file name.
Published 2007-11-01 · Modified
5.0EPSS 0.012
← Prev6 / 8Next →