← Back

Windows Nt

windows_nt

Vendor: Microsoft • 267 CVEs

CVEs (267)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jun 18, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive informati...Show more
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.Show less
1Microsoft
1Windows Nt
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.
1Microsoft
1Windows Nt
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability.
1Microsoft
1Windows Nt
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access.
1Microsoft
1Windows Nt
Apr 16, 2026
Feb 16, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the...Show more
The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities.Show less
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Feb 16, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuratio...Show more
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.Show less
1Microsoft
1Windows Nt
Apr 16, 2026
Feb 16, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabi...Show more
The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.Show less
1Microsoft
1Windows Nt
Apr 16, 2026
Feb 12, 2001
N/A· v4
7.1 HIGH· v3
2.1 LOW· v2
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to...Show more
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.Show less
1Microsoft
4Office
Windows 2000Windows Me+1 more
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials an...Show more
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.Show less
1Microsoft
1Windows Nt
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the "Terminal Server Login Buffer Overflow" vulnerability.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.
1Microsoft
5Windows 95
Windows 98Windows 98se+2 more
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connec...Show more
Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities. NOTE: this candidate may change significantly as the security community discusses the technical nature of NAPTHA and learns more about the affected applications. This candidate is at a higher level of abstraction than is typical for CVE.Show less
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Dec 31, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.
1Microsoft
3Systems Management Server
Windows 2000Windows Nt
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an...Show more
Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates.Show less
1Microsoft
1Windows Nt
Apr 16, 2026
Dec 14, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a larg...Show more
The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on the target machine.Show less
1Microsoft
2Internet Information Server
Windows Nt
Apr 16, 2026
Nov 14, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability.
1Microsoft
4Windows 2000
Windows 95Windows 98+1 more
Apr 16, 2026
Aug 29, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request i...Show more
Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.Show less
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jul 27, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Serve...Show more
The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability.Show less
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jul 25, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explor...Show more
The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative Shell Path" vulnerability.Show less
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jul 1, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
A Windows NT administrator account has the default name of Administrator.