Windows Nt
by Microsoft
CVEs (272)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-1362 | 0.00 | — | 0.01 | Dec 31, 1999 | Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters. | |||
| CVE-1999-1317 | 0.00 | — | 0.02 | Dec 31, 1999 | Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device. | |||
| CVE-1999-1222 | 0.00 | — | 0.05 | Dec 31, 1999 | Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup. | |||
| CVE-1999-1358 | 0.00 | — | 0.01 | Dec 31, 1999 | When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by… | |||
| CVE-1999-1363 | 0.00 | — | 0.01 | Dec 31, 1999 | Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool. | |||
| CVE-1999-1364 | 0.00 | — | 0.01 | Dec 31, 1999 | Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext. | |||
| CVE-1999-1359 | 0.00 | — | 0.04 | Dec 31, 1999 | When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies. | |||
| CVE-1999-1360 | 0.00 | — | 0.01 | Dec 31, 1999 | Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle. | |||
| CVE-1999-1455 | 0.00 | — | 0.04 | Dec 31, 1999 | RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host. | |||
| CVE-1999-1316 | 0.00 | — | 0.04 | Dec 31, 1999 | Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess. | |||
| CVE-1999-1294 | 0.00 | — | 0.02 | Dec 31, 1999 | Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission. | |||
| CVE-1999-1452 | 0.00 | — | 0.06 | Dec 31, 1999 | GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt. | |||
| CVE-1999-0824 | 0.00 | — | 0.01 | Nov 30, 1999 | A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users. | |||
| CVE-1999-0987 | 0.00 | — | 0.05 | Nov 18, 1999 | Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name. | |||
| CVE-1999-0728 | 0.00 | — | 0.06 | Jul 6, 1999 | A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them. | |||
| CVE-1999-1365 | 0.00 | — | 0.03 | Jun 28, 1999 | Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a… | |||
| CVE-1999-0717 | 0.00 | — | 0.06 | May 7, 1999 | A remote attacker can disable the virus warning mechanism in Microsoft Excel 97. | |||
| CVE-1999-0366 | 0.00 | — | 0.04 | Feb 8, 1999 | In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. | |||
| CVE-1999-0119 | 0.00 | — | 0.06 | Jan 19, 1999 | Windows NT 4.0 beta allows users to read and delete shares. | |||
| CVE-1999-0391 | 0.00 | — | 0.05 | Jan 5, 1999 | The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. |
- CVE-1999-1362Dec 31, 1999risk 0.00cvss —epss 0.01
Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters.
- CVE-1999-1317Dec 31, 1999risk 0.00cvss —epss 0.02
Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.
- CVE-1999-1222Dec 31, 1999risk 0.00cvss —epss 0.05
Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.
- CVE-1999-1358Dec 31, 1999risk 0.00cvss —epss 0.01
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by…
- CVE-1999-1363Dec 31, 1999risk 0.00cvss —epss 0.01
Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool.
- CVE-1999-1364Dec 31, 1999risk 0.00cvss —epss 0.01
Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.
- CVE-1999-1359Dec 31, 1999risk 0.00cvss —epss 0.04
When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies.
- CVE-1999-1360Dec 31, 1999risk 0.00cvss —epss 0.01
Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.
- CVE-1999-1455Dec 31, 1999risk 0.00cvss —epss 0.04
RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host.
- CVE-1999-1316Dec 31, 1999risk 0.00cvss —epss 0.04
Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.
- CVE-1999-1294Dec 31, 1999risk 0.00cvss —epss 0.02
Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission.
- CVE-1999-1452Dec 31, 1999risk 0.00cvss —epss 0.06
GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt.
- CVE-1999-0824Nov 30, 1999risk 0.00cvss —epss 0.01
A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.
- CVE-1999-0987Nov 18, 1999risk 0.00cvss —epss 0.05
Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.
- CVE-1999-0728Jul 6, 1999risk 0.00cvss —epss 0.06
A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.
- CVE-1999-1365Jun 28, 1999risk 0.00cvss —epss 0.03
Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a…
- CVE-1999-0717May 7, 1999risk 0.00cvss —epss 0.06
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
- CVE-1999-0366Feb 8, 1999risk 0.00cvss —epss 0.04
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.
- CVE-1999-0119Jan 19, 1999risk 0.00cvss —epss 0.06
Windows NT 4.0 beta allows users to read and delete shares.
- CVE-1999-0391Jan 5, 1999risk 0.00cvss —epss 0.05
The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.
Page 12 of 14