← Back

Windows Nt

windows_nt

Vendor: Microsoft • 267 CVEs

CVEs (267)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Windows Nt
Apr 16, 2026
Jul 25, 1997
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain direct...Show more
The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.Show less
1Microsoft
1Windows Nt
Apr 16, 2026
Jul 10, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorr...Show more
Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.Show less
2Microsoft
Sco
4Openserver
Windows 2000Windows 95+1 more
Apr 16, 2026
Jul 1, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
4Freebsd
LinuxMicrosoft+1 more
4Freebsd
Linux KernelNetbsd+1 more
Apr 16, 2026
Jul 1, 1997
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Listening TCP ports are sequentially allocated, allowing spoofing attacks.
1Microsoft
1Windows Nt
Apr 16, 2026
Jun 10, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.
1Microsoft
1Windows Nt
Apr 16, 2026
Jun 1, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.
1Microsoft
1Windows Nt
Apr 16, 2026
Apr 2, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel...Show more
Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.Show less
1Microsoft
1Windows Nt
Apr 16, 2026
Apr 1, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service through Winpopup using large user names.
2Gnu
Microsoft
4Finger Service
FingerdWindows 2000+1 more
Apr 16, 2026
Mar 1, 1997
N/A· v4
N/A· v3
0.0 LOW· v2
A version of finger is running that exposes valid user information to any entity on the network.
1Microsoft
1Windows Nt
Apr 16, 2026
Feb 7, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.
1Microsoft
1Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.
1Microsoft
1Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdo...Show more
A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking.Show less
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
9.3 HIGH· v2
.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
The registry in Windows NT can be accessed remotely by users who are not administrators.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
10.0 HIGH· v2
A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
4.6 MEDIUM· v2
A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Incr...Show more
A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input.Show less
1Microsoft
4Outlook
Windows 2000Windows 95+1 more
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
A NETBIOS/SMB share password is the default, null, or missing.
1Microsoft
2Windows 2000
Windows Nt
May 28, 2026
Jan 1, 1997
N/A· v4
9.1 CRITICAL· v3
7.5 HIGH· v2
IP forwarding is enabled on a machine which is not a router or firewall.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
A Windows NT local user or administrator account has a default, null, blank, or missing password.