← Back

Windows Nt

windows_nt

Vendor: Microsoft • 267 CVEs

CVEs (267)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Dec 1, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
1Microsoft
1Windows Nt
Apr 16, 2026
Nov 30, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.
1Microsoft
1Windows Nt
Apr 16, 2026
Nov 18, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.
1Microsoft
3Windows 2000
Windows 98Windows Nt
Apr 16, 2026
Nov 17, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.
1Microsoft
1Windows Nt
Apr 16, 2026
Nov 4, 1999
N/A· v4
N/A· v3
7.2 HIGH· v2
The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.
1Microsoft
1Windows Nt
Apr 16, 2026
Nov 4, 1999
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.
1Microsoft
1Windows Nt
Apr 16, 2026
Oct 26, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.
1Microsoft
4Terminal Server
Windows 95Windows 98se+1 more
Apr 16, 2026
Sep 20, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.
1Microsoft
1Windows Nt
Apr 16, 2026
Sep 17, 1999
N/A· v4
N/A· v3
9.0 HIGH· v2
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
1Microsoft
1Windows Nt
Apr 16, 2026
Aug 24, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jul 29, 1999
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
1Microsoft
1Windows Nt
Apr 16, 2026
Jul 23, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service in Windows NT messenger service through a long username.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jul 20, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
1Microsoft
1Windows Nt
Apr 16, 2026
Jul 6, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.
1Microsoft
4Windows 2000
Windows 95Windows 98+1 more
Apr 16, 2026
Jul 3, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jun 30, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
1Microsoft
1Windows Nt
Apr 16, 2026
Jun 30, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service in RAS/PPTP on NT systems.
1Microsoft
1Windows Nt
Apr 16, 2026
Jun 28, 1999
N/A· v4
N/A· v3
7.2 HIGH· v2
Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to b...Show more
Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default.Show less
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jun 23, 1999
N/A· v4
N/A· v3
7.1 HIGH· v2
The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.
1Microsoft
3Internet Information Server
Windows 2000Windows Nt
Apr 16, 2026
Jun 16, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.