National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

Search Parameters:
  • Contains Software Flaws (CVE)
  • CPE Product Version: cpe:/o:microsoft:windows_nt:4.0:sp2:~~embedded~~x86~
There are 260 matching records.
Displaying matches 241 through 260.
Vuln ID Summary CVSS Severity
CVE-1999-1387

Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.

Published: April 02, 1997; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-1999-0292

Denial of service through Winpopup using large user names.

Published: April 01, 1997; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-1999-0612

A version of finger is running that exposes valid user information to any entity on the network.

Published: March 01, 1997; 12:00:00 AM -05:00
    V2: 0.0 LOW
CVE-1999-0228

Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.

Published: February 07, 1997; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-1999-0249

Windows NT RSHSVC program allows remote users to execute arbitrary commands.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 7.2 HIGH
CVE-1999-0274

Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-1999-0496

A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 7.2 HIGH
CVE-1999-0499

NETBIOS share information may be published through SNMP registry keys in NT.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-1999-0503

A Windows NT local user or administrator account has a guessable password.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 7.2 HIGH
CVE-1999-0504

A Windows NT local user or administrator account has a default, null, blank, or missing password.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-1999-0511

IP forwarding is enabled on a machine which is not a router or firewall.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-1999-0519

A NETBIOS/SMB share password is the default, null, or missing.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-1999-0534

A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 4.6 MEDIUM
CVE-1999-0535

A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 10.0 HIGH
CVE-1999-0562

The registry in Windows NT can be accessed remotely by users who are not administrators.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-1999-0572

.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 9.3 HIGH
CVE-1999-0575

A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-1999-0576

A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 7.5 HIGH
CVE-1999-0582

A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.

Published: January 01, 1997; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM
CVE-1999-0077

Predictable TCP sequence numbers allow spoofing.

Published: January 01, 1995; 12:00:00 AM -05:00
    V2: 5.0 MEDIUM