Page 122 of 637 results (0.026 seconds)

CVSS: 4.6EPSS: 0%CPEs: 2EXPL: 0

When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only. • http://support.microsoft.com/support/kb/articles/q157/6/73.asp http://www.iss.net/security_center/static/7400.php •

CVSS: 5.0EPSS: 0%CPEs: 2EXPL: 1

NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it. • https://www.exploit-db.com/exploits/23264 http://marc.info/?l=bugtraq&m=94398141118586&w=2 •

CVSS: 5.0EPSS: 0%CPEs: 3EXPL: 1

Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word. • https://www.exploit-db.com/exploits/19633 http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ249973 http://xforce.iss.net/search.php3?type=2&pattern=win-malformed-rtf-control-word https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-005 •

CVSS: 7.5EPSS: 1%CPEs: 6EXPL: 1

DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes. • https://www.exploit-db.com/exploits/19451 http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ216141 http://www.securityfocus.com/bid/578 • CWE-16: Configuration •

CVSS: 6.2EPSS: 0%CPEs: 8EXPL: 1

Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file. • https://www.exploit-db.com/exploits/19440 http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ237185 https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-026 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •