Microsoft / Windows NT
209 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2008-5232 | Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Micros… | HIGH | 9.3 | Nov 26, 2008 |
| CVE-2007-6026 | Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-as… | HIGH | 9.3 | Nov 20, 2007 |
| CVE-2002-2401 | NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users… | LOW | 3.6 | Nov 1, 2007 |
| CVE-2003-1407 | Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the cd command. | HIGH | 7.2 | Oct 20, 2007 |
| CVE-2007-1973 | Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via t… | MEDIUM | 6.9 | Apr 11, 2007 |
| CVE-2007-1912 | Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file. | MEDIUM | 6.8 | Apr 10, 2007 |
| CVE-2006-2379 | Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute… | HIGH | 9.3 | Jun 13, 2006 |
| CVE-2006-1184 | Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial o… | MEDIUM | 5.0 | May 9, 2006 |
| CVE-2006-0034 | Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Wind… | HIGH | 7.5 | May 9, 2006 |
| CVE-2006-1591 | Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to execute arbitrary code via crafted embedded image data in a… | MEDIUM | 5.1 | Apr 3, 2006 |
| CVE-2006-0988 | The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows rec… | HIGH | 7.8 | Mar 3, 2006 |
| CVE-2005-4717 | Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers t… | MEDIUM | 5.0 | Feb 15, 2006 |
| CVE-2006-0010 | Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote at… | HIGH | 9.3 | Jan 10, 2006 |
| CVE-2005-2827 | The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow via steps… | HIGH | 7.2 | Dec 14, 2005 |
| CVE-2002-2073 | Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary we… | MEDIUM | 4.3 | Jul 14, 2005 |
| CVE-2002-2028 | The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which make… | LOW | 2.1 | Jul 14, 2005 |
| CVE-2005-2150 | Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which al… | MEDIUM | 5.0 | Jul 11, 2005 |
| CVE-2000-1227 | Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots request… | MEDIUM | 5.0 | Jun 28, 2005 |
| CVE-2002-1712 | Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FI… | MEDIUM | 5.0 | Jun 21, 2005 |
| CVE-2005-1935 | Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested… | HIGH | 7.5 | Jun 9, 2005 |
| CVE-2001-1452 | By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to… | HIGH | 7.5 | Apr 21, 2005 |
| CVE-2000-1218 | The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Win… | CRITICAL | 9.8 | Apr 21, 2005 |
| CVE-1999-1579 | The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause… | MEDIUM | 5.0 | Apr 21, 2005 |
| CVE-2005-1184 | The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the correct sequenc… | MEDIUM | 5.0 | Apr 19, 2005 |
| CVE-2005-0416 | The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to execu… | HIGH | 7.5 | Feb 14, 2005 |
Showing 1 to 25 of 209 CVEs