Vulnerabilities
Vulnerable Software
Microsoft:  >> Windows Nt  >> 4.0  Security Vulnerabilities
Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability.
CVSS Score
7.5
EPSS Score
0.307
Published
2000-04-19
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
CVSS Score
9.8
EPSS Score
0.022
Published
2000-04-14
The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users.
CVSS Score
7.2
EPSS Score
0.004
Published
2000-04-12
After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.
CVSS Score
7.2
EPSS Score
0.008
Published
2000-04-11
Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request.
CVSS Score
2.1
EPSS Score
0.008
Published
2000-03-30
Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.
CVSS Score
7.2
EPSS Score
0.017
Published
2000-02-18
The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.
CVSS Score
4.6
EPSS Score
0.004
Published
2000-02-14
The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.
CVSS Score
2.1
EPSS Score
0.029
Published
2000-02-04
Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.
CVSS Score
2.1
EPSS Score
0.001
Published
2000-02-04
The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creation" vulnerability.
CVSS Score
3.6
EPSS Score
0.021
Published
2000-02-01


Contact Us

Shodan ® - All rights reserved