Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Microsoft Subscribe
Filtered by product Windows Nt
Total 284 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-2073 1 Microsoft 3 Site Server, Site Server Commerce, Windows Nt 2016-10-17 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp.
CVE-1999-1387 1 Microsoft 1 Windows Nt 2016-10-17 5.0 MEDIUM N/A
Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.
CVE-1999-1361 1 Microsoft 1 Windows Nt 2016-10-17 6.4 MEDIUM N/A
Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages.
CVE-1999-1132 1 Microsoft 1 Windows Nt 2016-10-17 5.0 MEDIUM N/A
Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.
CVE-1999-0819 1 Microsoft 2 Windows 2000, Windows Nt 2016-10-17 5.0 MEDIUM N/A
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
CVE-2007-3482 2 Apple, Microsoft 2 Safari, Windows Nt 2008-11-14 7.8 HIGH N/A
Cross-domain vulnerability in Apple Safari for Windows 3.0.1 allows remote attackers to bypass the "same origin policy" and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute.
CVE-2000-0544 1 Microsoft 2 Windows 2000, Windows Nt 2008-09-10 5.0 MEDIUM N/A
Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.
CVE-2000-0197 1 Microsoft 1 Windows Nt 2008-09-10 4.6 MEDIUM N/A
The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.
CVE-2000-0155 1 Microsoft 3 Windows 95, Windows 98, Windows Nt 2008-09-09 7.2 HIGH N/A
Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.
CVE-1999-0824 1 Microsoft 1 Windows Nt 2008-09-09 4.6 MEDIUM N/A
A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.
CVE-1999-0975 1 Microsoft 3 Windows 95, Windows 98, Windows Nt 2008-09-09 4.6 MEDIUM N/A
The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.
CVE-1999-0256 2 Jgaa, Microsoft 3 Warftpd, Windows 95, Windows Nt 2008-09-09 7.5 HIGH N/A
Buffer overflow in War FTP allows remote execution of commands.
CVE-1999-0225 1 Microsoft 1 Windows Nt 2008-09-09 5.0 MEDIUM N/A
Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.
CVE-1999-0153 2 Microsoft, Sco 4 Windows 2000, Windows 95, Windows Nt and 1 more 2008-09-09 5.0 MEDIUM N/A
Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
CVE-1999-0016 6 Cisco, Gnu, Hp and 3 more 8 Ios, Inet, Hp-ux and 5 more 2008-09-09 5.0 MEDIUM N/A
Land IP denial of service.
CVE-2002-2413 2 Deerfield, Microsoft 3 Website Pro, Windows 9x, Windows Nt 2008-09-05 5.0 MEDIUM N/A
WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8.3 file name.
CVE-2002-0421 1 Microsoft 1 Windows Nt 2008-09-05 5.0 MEDIUM N/A
IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.
CVE-2001-0281 1 Microsoft 1 Windows Nt 2008-09-05 7.2 HIGH N/A
Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.
CVE-1999-1358 1 Microsoft 2 Windows 2000, Windows Nt 2008-09-05 4.6 MEDIUM N/A
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.
CVE-1999-1364 1 Microsoft 1 Windows Nt 2008-09-05 2.1 LOW N/A
Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.