20 results (0.006 seconds)

CVSS: 9.3EPSS: 67%CPEs: 86EXPL: 0

10 Jan 2006 — Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression. Desbordamiento de búfer basado en memoria dinámica en T2EMBED.DLL en Microsoft Windows 2000 SP4, XP SP1 y SP2 y Server 2003 hasta la versión SP1, Windows 98 y Windows ME permite a atacant... • http://seclists.org/fulldisclosure/2006/Jan/363 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.8EPSS: 1%CPEs: 1EXPL: 0

12 Mar 2001 — NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access. • http://razor.bindview.com/publish/advisories/adv_NTLMSSP.html •

CVSS: 7.5EPSS: 19%CPEs: 1EXPL: 0

12 Mar 2001 — Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability. • http://www.securityfocus.com/bid/2368 •

CVSS: 9.8EPSS: 0%CPEs: 7EXPL: 0

04 Feb 2000 — A Windows NT administrator account has the default name of Administrator. • https://www.cve.org/CVERecord?id=CVE-1999-0585 •

CVSS: 10.0EPSS: 10%CPEs: 11EXPL: 0

04 Feb 2000 — A system does not present an appropriate legal message or warning to a user who is accessing it. • http://ciac.llnl.gov/ciac/bulletins/j-043.shtml •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

20 Jan 2000 — A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded. • https://exchange.xforce.ibmcloud.com/vulnerabilities/216 •

CVSS: 7.5EPSS: 17%CPEs: 1EXPL: 0

31 Dec 1999 — Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries. • http://support.microsoft.com/support/kb/articles/q196/2/70.asp •

CVSS: 7.5EPSS: 14%CPEs: 1EXPL: 0

31 Dec 1999 — Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface. • http://support.microsoft.com/support/kb/articles/Q192/7/74.ASP •

CVSS: 7.8EPSS: 1%CPEs: 1EXPL: 0

31 Dec 1999 — Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device. • http://marc.info/?l=ntbugtraq&m=92127046701349&w=2 •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

31 Dec 1999 — Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters. • http://support.microsoft.com/support/kb/articles/q160/6/01.asp •