Windows NT 4.0 beta allows users to read and delete shares.
Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.
The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and imperso…
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
A system-critical Windows NT file or directory has inappropriate permissions.
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.
Windows NT automatically logs in an administrator upon rebooting.
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
Buffer overflow in NetMeeting allows denial of service and remote command execution.
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (…
A Windows NT domain user or administrator account has a guessable password.
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message…
NT users can gain debug-level access on a system process using the Sechole exploit.
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP fra…
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the regi…
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a…
A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript…
Bonk variation of teardrop IP fragmentation denial of service.
Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a…
Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.
All records in a WINS database can be deleted through SNMP for a denial of service.
IIS newdsn.exe CGI script allows remote users to overwrite files.
Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.