CVEs (267)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option. |
Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry. |
Buffer overflow in Windows NT 4.0 help file utility via a malformed help file. |
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013. |
1Microsoft 5Excel Windows 2000Windows 95+2 moreApr 16, 2026 May 7, 1999 N/A· v4 N/A· v3 2.6 LOW· v2 A remote attacker can disable the virus warning mechanism in Microsoft Excel 97. |
1Microsoft 3Windows 95 Windows 98Windows NtApr 16, 2026 Apr 12, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files. |
The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges. |
1Microsoft 3Windows 95 Windows 98Windows NtApr 16, 2026 Mar 8, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables. |
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs. |
1Microsoft 3Backoffice Windows 2000Windows NtApr 16, 2026 Feb 12, 1999 N/A· v4 N/A· v3 2.1 LOW· v2 The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. |
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. |
Windows NT 4.0 beta allows users to read and delete shares. |
1Microsoft 3Terminal Server Windows 2000Windows NtApr 16, 2026 Jan 5, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. |
The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. |
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. |
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. |
A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. |
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. |
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. |
A system-critical Windows NT file or directory has inappropriate permissions. |