| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A password for accessing a WWW URL is guessable. |
| An SSH server allows authentication through the .rhosts file. |
| Windows NT automatically logs in an administrator upon rebooting. |
| An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities. |
| Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. |
| A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking. |
| A network service is running on a nonstandard port. |
| A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data. |
| A filter in a router or firewall allows unusual fragmented packets. |
| A system does not present an appropriate legal message or warning to a user who is accessing it. |
| The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. |
| A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive. |
| A Windows NT log file has an inappropriate maximum size or retention period. |
| A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire. |
| In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc. |
| An incorrect configuration of the WebStore 1.0 shopping cart CGI program "web_store.cgi" could disclose private information. |
| An incorrect configuration of the Order Form 1.0 shopping cart CGI program could disclose private information. |
| nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information. |
| A system-critical Windows NT registry key has an inappropriate value. |
| A version of finger is running that exposes valid user information to any entity on the network. |