National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

Search Parameters:
  • Contains Software Flaws (CVE)
  • CPE Product Version: cpe:/o:microsoft:windows_nt:4.0:sp2:workstation
There are 180 matching records.
Displaying matches 121 through 140.
Vuln ID Summary CVSS Severity
CVE-2000-0089

The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.

Published: February 04, 2000; 12:00:00 AM -05:00
V2: 2.1 LOW
CVE-2000-0129

Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.

Published: February 04, 2000; 12:00:00 AM -05:00
V2: 2.1 LOW
CVE-2000-0121

The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creation" vulnerability.

Published: February 01, 2000; 12:00:00 AM -05:00
V2: 3.6 LOW
CVE-1999-0595

A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.

Published: January 20, 2000; 12:00:00 AM -05:00
V2: 2.1 LOW
CVE-2000-0070

NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC Port Request."

Published: January 12, 2000; 12:00:00 AM -05:00
V2: 7.2 HIGH
CVE-1999-1084

The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.

Published: December 31, 1999; 12:00:00 AM -05:00
V2: 4.6 MEDIUM
CVE-1999-1127

Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability.

Published: December 31, 1999; 12:00:00 AM -05:00
V2: 5.0 MEDIUM
CVE-1999-1132

Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.

Published: December 31, 1999; 12:00:00 AM -05:00
V2: 5.0 MEDIUM
CVE-1999-1157

Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.

Published: December 31, 1999; 12:00:00 AM -05:00
V2: 5.0 MEDIUM
CVE-1999-1222

Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.

Published: December 31, 1999; 12:00:00 AM -05:00
V2: 5.0 MEDIUM
CVE-1999-1360

Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.

Published: December 31, 1999; 12:00:00 AM -05:00
V2: 2.1 LOW
CVE-1999-1362

Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters.

Published: December 31, 1999; 12:00:00 AM -05:00
V2: 2.1 LOW
CVE-1999-1363

Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool.

Published: December 31, 1999; 12:00:00 AM -05:00
V2: 2.1 LOW
CVE-1999-1364

Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.

Published: December 31, 1999; 12:00:00 AM -05:00
V2: 2.1 LOW
CVE-1999-1452

GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt.

Published: December 31, 1999; 12:00:00 AM -05:00
V2: 2.1 LOW
CVE-1999-1455

RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host.

Published: December 31, 1999; 12:00:00 AM -05:00
V2: 7.5 HIGH
CVE-1999-0994

Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.

Published: December 16, 1999; 12:00:00 AM -05:00
V2: 5.0 MEDIUM
CVE-1999-0995

Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request."

Published: December 16, 1999; 12:00:00 AM -05:00
V2: 7.8 HIGH
CVE-1999-0975

The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.

Published: December 10, 1999; 12:00:00 AM -05:00
V2: 4.6 MEDIUM
CVE-1999-0819

NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.

Published: December 01, 1999; 12:00:00 AM -05:00
V2: 5.0 MEDIUM