| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager. |
| Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request. |
| Denial of service in RAS/PPTP on NT systems. |
| Predictable TCP sequence numbers allow spoofing. |
| The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. |
| A system does not present an appropriate legal message or warning to a user who is accessing it. |
| Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs. |
| The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. |
| A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. |
| The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. |
| Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service. |
| A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. |
| A Windows NT administrator account has the default name of Administrator. |
| In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. |
| A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. |
| Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission. |
| A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories. |
| NT users can gain debug-level access on a system process using the Sechole exploit. |
| Denial of service in Windows NT messenger service through a long username. |
| Windows NT 4.0 beta allows users to read and delete shares. |