National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

Search Parameters:
  • Contains Software Flaws (CVE)
  • CPE Product Version: cpe:/o:microsoft:windows_nt:4.0:sp2:~~embedded~~x86~
There are 260 matching records.
Displaying matches 201 through 220.
Vuln ID Summary CVSS Severity
CVE-1999-0716

Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.

Published: May 17, 1999; 12:00:00 AM -04:00
    V2: 4.6 MEDIUM
CVE-1999-0717

A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.

Published: May 07, 1999; 12:00:00 AM -04:00
    V2: 2.6 LOW
CVE-1999-0444

Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.

Published: April 12, 1999; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-1999-0382

The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.

Published: March 12, 1999; 12:00:00 AM -05:00
    V2: 7.2 HIGH
CVE-1999-1254

Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.

Published: March 08, 1999; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-1999-0376

Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.

Published: February 20, 1999; 12:00:00 AM -05:00
    V2: 4.6 MEDIUM
CVE-1999-0372

The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.

Published: February 12, 1999; 12:00:00 AM -05:00
    V2: 2.1 LOW
CVE-1999-0119

Windows NT 4.0 beta allows users to read and delete shares.

Published: January 19, 1999; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-1999-0391

The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.

Published: January 05, 1999; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-1999-0285

Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.

Published: January 01, 1999; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-1999-0384

The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.

Published: January 01, 1999; 12:00:00 AM -05:00
    V2: 4.6 MEDIUM
CVE-1999-0549

Windows NT automatically logs in an administrator upon rebooting.

Published: January 01, 1999; 12:00:00 AM -05:00
    V2: 7.2 HIGH
CVE-1999-0560

A system-critical Windows NT file or directory has inappropriate permissions.

Published: January 01, 1999; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-1999-0570

Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.

Published: January 01, 1999; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-1999-0577

A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.

Published: January 01, 1999; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-1999-0578

A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.

Published: January 01, 1999; 12:00:00 AM -05:00
    V2: 4.6 MEDIUM
CVE-1999-0579

A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.

Published: January 01, 1999; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-1999-0581

The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.

Published: January 01, 1999; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-1999-0593

The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.

Published: January 01, 1999; 12:00:00 AM -05:00
    V2: 4.9 MEDIUM
CVE-1999-1291

TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.

Published: October 05, 1998; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM