| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed request. |
| Teardrop IP denial of service. |
| Land IP denial of service. |
| Listening TCP ports are sequentially allocated, allowing spoofing attacks. |
| Denial of service in RAS/PPTP on NT systems. |
| Denial of service in Windows NT messenger service through a long username. |
| Buffer overflow in War FTP allows remote execution of commands. |
| Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection. |
| Denial of service through Winpopup using large user names. |
| Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs. |
| The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges. |
| The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. |
| A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin. |
| NETBIOS share information may be published through SNMP registry keys in NT. |
| A Windows NT domain user or administrator account has a default, null, blank, or missing password. |
| A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. |
| A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. |
| The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. |
| A version of finger is running that exposes valid user information to any entity on the network. |
| A remote attacker can disable the virus warning mechanism in Microsoft Excel 97. |