Page 37 of 213 results (0.012 seconds)

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ234557 http://www.securityfocus.com/bid/499 https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-023 • CWE-20: Improper Input Validation •

CVSS: 7.1EPSS: 0%CPEs: 3EXPL: 0

The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ233323 http://www.ciac.org/ciac/bulletins/j-049.shtml http://www.securityfocus.com/bid/478 https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-021 •

CVSS: 10.0EPSS: 90%CPEs: 4EXPL: 5

Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions. • https://www.exploit-db.com/exploits/19247 https://www.exploit-db.com/exploits/19245 https://www.exploit-db.com/exploits/19248 https://www.exploit-db.com/exploits/16468 https://www.exploit-db.com/exploits/19246 http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ234905 http://www.ciac.org/ciac/bulletins/j-048.shtml http://www.eeye.com/html/Research/Advisories/AD06081999.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-019 https • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 5.0EPSS: 0%CPEs: 7EXPL: 1

Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option. • https://www.exploit-db.com/exploits/19196 http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ230681 https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-017 • CWE-255: Credentials Management Errors •

CVSS: 4.6EPSS: 0%CPEs: 3EXPL: 1

Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry. • https://www.exploit-db.com/exploits/19211 http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ230677 https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-016 •