Vulnerabilities
Vulnerable Software
Microsoft:  >> Windows 95  Security Vulnerabilities
Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name.
CVSS Score
5.0
EPSS Score
0.392
Published
2000-05-02
Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability.
CVSS Score
5.0
EPSS Score
0.166
Published
2000-03-04
Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.
CVSS Score
7.2
EPSS Score
0.017
Published
2000-02-18
Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.
CVSS Score
2.1
EPSS Score
0.001
Published
2000-02-04
Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.
CVSS Score
4.6
EPSS Score
0.01
Published
1999-12-31
Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive.
CVSS Score
5.0
EPSS Score
0.367
Published
1999-12-31
The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.
CVSS Score
4.6
EPSS Score
0.003
Published
1999-12-10
A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.
CVSS Score
7.8
EPSS Score
0.243
Published
1999-11-29
The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability.
CVSS Score
7.6
EPSS Score
0.229
Published
1999-11-12
Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.
CVSS Score
7.5
EPSS Score
0.042
Published
1999-09-20


Contact Us

Shodan ® - All rights reserved