Microsoft
microsoft
15,300 CVEs • 1,060 products
Products (1,060)
Click to collapseToggle
Products (1,060)
Click to collapse
CVEs (15,300)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. |
A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories. |
A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdo...Show more |
.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks. |
The registry in Windows NT can be accessed remotely by users who are not administrators. |
A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness. |
A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Incr...Show more |
1Microsoft 4Outlook Windows 2000Windows 95+1 moreApr 16, 2026 Jan 1, 1997 N/A· v4 N/A· v3 7.5 HIGH· v2 A NETBIOS/SMB share password is the default, null, or missing. |
A NETBIOS/SMB share password is guessable. |
1Microsoft 2Windows 2000 Windows NtMay 28, 2026 Jan 1, 1997 N/A· v4 9.1 CRITICAL· v3 7.5 HIGH· v2 IP forwarding is enabled on a machine which is not a router or firewall. |
A Windows NT local user or administrator account has a default, null, blank, or missing password. |
A Windows NT local user or administrator account has a guessable password. |
NETBIOS share information may be published through SNMP registry keys in NT. |
A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin. |
Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jan 1, 1997 N/A· v4 N/A· v3 7.5 HIGH· v2 IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. |
Windows NT RSHSVC program allows remote users to execute arbitrary commands. |
Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share. |
1Microsoft 1Internet Information Services Apr 16, 2026 Feb 25, 1996 N/A· v4 N/A· v3 10.0 HIGH· v2 IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. |
Predictable TCP sequence numbers allow spoofing. |