Vulnerabilities
Vulnerable Software
Microsoft:  >> Windows Nt  >> 3.5.1  Security Vulnerabilities
Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.
CVSS Score
5.0
EPSS Score
0.148
Published
1999-12-31
Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.
CVSS Score
4.6
EPSS Score
0.011
Published
1999-12-31
When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.
CVSS Score
4.6
EPSS Score
0.004
Published
1999-12-31
When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies.
CVSS Score
7.5
EPSS Score
0.089
Published
1999-12-31
Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters.
CVSS Score
2.1
EPSS Score
0.002
Published
1999-12-31
Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool.
CVSS Score
2.1
EPSS Score
0.003
Published
1999-12-31
RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host.
CVSS Score
7.5
EPSS Score
0.07
Published
1999-12-31
Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.
CVSS Score
10.0
EPSS Score
0.055
Published
1999-11-18
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
CVSS Score
6.2
EPSS Score
0.028
Published
1999-07-29
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
CVSS Score
7.8
EPSS Score
0.195
Published
1999-07-20


Contact Us

Shodan ® - All rights reserved