Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.
Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.
Denial of service in IIS using long URLs.
Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by…
Denial of service through Winpopup using large user names.
Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.
A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.
.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.
IP forwarding is enabled on a machine which is not a router or firewall.
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.
NETBIOS share information may be published through SNMP registry keys in NT.
A Windows NT local user or administrator account has a default, null, blank, or missing password.
A NETBIOS/SMB share password is guessable.
A NETBIOS/SMB share password is the default, null, or missing.
The registry in Windows NT can be accessed remotely by users who are not administrators.
A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Righ…
A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.
Windows NT RSHSVC program allows remote users to execute arbitrary commands.
A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.
A Windows NT local user or administrator account has a guessable password.
Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.
Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.
IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.
Predictable TCP sequence numbers allow spoofing.