National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

Search Parameters:
  • Contains Software Flaws (CVE)
  • CPE Product Version: cpe:/o:microsoft:windows_nt:4.0:sp2:~~embedded~~x64~
There are 260 matching records.
Displaying matches 181 through 200.
Vuln ID Summary CVSS Severity
CVE-2000-0073

Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.

Published: November 17, 1999; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-1999-0898

Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.

Published: November 04, 1999; 12:00:00 AM -05:00
    V2: 7.2 HIGH
CVE-1999-0899

The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.

Published: November 04, 1999; 12:00:00 AM -05:00
    V2: 7.2 HIGH
CVE-1999-1234

LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.

Published: October 26, 1999; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-1999-0909

Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.

Published: September 20, 1999; 12:00:00 AM -04:00
    V2: 7.5 HIGH
CVE-1999-0886

The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.

Published: September 17, 1999; 12:00:00 AM -04:00
    V2: 9.0 HIGH
CVE-2000-0328

Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.

Published: August 24, 1999; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-1999-0700

Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.

Published: July 29, 1999; 12:00:00 AM -04:00
    V2: 6.2 MEDIUM
CVE-1999-0224

Denial of service in Windows NT messenger service through a long username.

Published: July 23, 1999; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-1999-0721

Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.

Published: July 20, 1999; 12:00:00 AM -04:00
    V2: 7.8 HIGH
CVE-1999-0728

A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.

Published: July 06, 1999; 12:00:00 AM -04:00
    V2: 7.8 HIGH
CVE-1999-0918

Denial of service in various Windows systems via malformed, fragmented IGMP packets.

Published: July 03, 1999; 12:00:00 AM -04:00
    V2: 7.8 HIGH
CVE-1999-0140

Denial of service in RAS/PPTP on NT systems.

Published: June 30, 1999; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-1999-0726

An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.

Published: June 30, 1999; 12:00:00 AM -04:00
    V2: 7.8 HIGH
CVE-1999-1365

Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default.

Published: June 28, 1999; 12:00:00 AM -04:00
    V2: 7.2 HIGH
CVE-1999-0723

The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.

Published: June 23, 1999; 12:00:00 AM -04:00
    V2: 7.1 HIGH
CVE-1999-0874

Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.

Published: June 16, 1999; 12:00:00 AM -04:00
    V2: 10.0 HIGH
CVE-1999-0755

Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.

Published: May 27, 1999; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-1999-0715

Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.

Published: May 20, 1999; 12:00:00 AM -04:00
    V2: 4.6 MEDIUM
CVE-1999-0489

MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.

Published: May 17, 1999; 12:00:00 AM -04:00
    V2: 10.0 HIGH