VYPR

Windows Nt

by Microsoft

CVEs (272)

  • CVE-2002-2401Dec 31, 2002
    risk 0.00cvss —epss 0.02

    NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs.

  • CVE-2002-1184Nov 12, 2002
    risk 0.00cvss —epss 0.03

    The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other…

  • CVE-2002-0366Jul 3, 2002
    risk 0.00cvss —epss 0.03

    Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.

  • CVE-2002-0151Apr 4, 2002
    risk 0.00cvss —epss 0.03

    Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.

  • CVE-2001-1288Jul 27, 2001
    risk 0.00cvss —epss 0.06

    Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt and pressing the F7 and enter keys several times while the command is executing, possibly related to an exception handling error in csrss.exe.

  • CVE-2001-1244Jul 7, 2001
    risk 0.00cvss —epss 0.22

    Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that…

  • CVE-2001-0373Jun 18, 2001
    risk 0.00cvss —epss 0.02

    The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.

  • CVE-2001-0281May 3, 2001
    risk 0.00cvss —epss 0.05

    Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.

  • CVE-2001-0016Mar 12, 2001
    risk 0.00cvss —epss 0.02

    NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access.

  • CVE-2001-0047Feb 16, 2001
    risk 0.00cvss —epss 0.06

    The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities.

  • CVE-2001-0046Feb 16, 2001
    risk 0.00cvss —epss 0.05

    The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.

  • CVE-2000-0663Jul 25, 2000
    risk 0.00cvss —epss 0.02

    The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative…

  • CVE-1999-0585Jul 1, 2000
    risk 0.00cvss —epss 0.02

    A Windows NT administrator account has the default name of Administrator.

  • CVE-1999-0590Jun 1, 2000
    risk 0.00cvss —epss 0.06

    A system does not present an appropriate legal message or warning to a user who is accessing it.

  • CVE-2000-0259Apr 12, 2000
    risk 0.00cvss —epss 0.01

    The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users.

  • CVE-1999-0701Apr 11, 2000
    risk 0.00cvss —epss 0.02

    After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.

  • CVE-2000-0197Feb 14, 2000
    risk 0.00cvss —epss 0.02

    The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.

  • CVE-2000-0089Feb 4, 2000
    risk 0.00cvss —epss 0.02

    The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.

  • CVE-1999-0595Jan 20, 2000
    risk 0.00cvss —epss 0.02

    A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.

  • CVE-2000-0070Jan 12, 2000
    risk 0.00cvss —epss 0.02

    NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC Port Request."

Page 11 of 14