9 results (0.005 seconds)

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

28 Jun 2007 — Cross-domain vulnerability in Apple Safari for Windows 3.0.1 allows remote attackers to bypass the "same origin policy" and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute. Una vulnerabilidad de tipo cross-domain en Apple Safari para Windows versión 3.0.1, permite a atacantes remotos omitir la "same origin policy" y acceder a información restringida de otros dominios por medio de JavaScript que sobrescrib... • http://osvdb.org/38860 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.8EPSS: 1%CPEs: 1EXPL: 0

12 Mar 2001 — NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access. • http://razor.bindview.com/publish/advisories/adv_NTLMSSP.html •

CVSS: 7.5EPSS: 19%CPEs: 1EXPL: 0

12 Mar 2001 — Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability. • http://www.securityfocus.com/bid/2368 •

CVSS: 7.5EPSS: 17%CPEs: 1EXPL: 0

31 Dec 1999 — Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries. • http://support.microsoft.com/support/kb/articles/q196/2/70.asp •

CVSS: 7.5EPSS: 14%CPEs: 1EXPL: 0

31 Dec 1999 — Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface. • http://support.microsoft.com/support/kb/articles/Q192/7/74.ASP •

CVSS: 7.8EPSS: 1%CPEs: 1EXPL: 0

31 Dec 1999 — Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device. • http://marc.info/?l=ntbugtraq&m=92127046701349&w=2 •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

31 Dec 1999 — Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters. • http://support.microsoft.com/support/kb/articles/q160/6/01.asp •

CVSS: 8.1EPSS: 7%CPEs: 1EXPL: 0

31 Dec 1999 — RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host. • http://support.microsoft.com/support/kb/articles/q158/3/20.asp •

CVSS: 7.5EPSS: 4%CPEs: 1EXPL: 1

10 Jul 1997 — Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session. • http://www.securityfocus.com/archive/1/7219 •