← Back
CWE-287

4,482 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,482)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Terminal Server
Apr 16, 2026
Aug 9, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.
1Microsoft
1Windows Nt
Apr 16, 2026
Feb 8, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.