Microsoft

Windows Nt

263 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.17%
  • Published 31.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to forms...

  • EPSS 0.64%
  • Published 31.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs.

  • EPSS 7.7%
  • Published 23.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.

  • EPSS 4.36%
  • Published 23.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in...

  • EPSS 10.15%
  • Published 23.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet.

  • EPSS 9.89%
  • Published 23.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."

Exploit
  • EPSS 11.91%
  • Published 11.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).

  • EPSS 1.41%
  • Published 12.11.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers...

  • EPSS 23.38%
  • Published 11.10.2002 04:00:00
  • Last modified 03.04.2025 01:03:51

Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka...

  • EPSS 71.91%
  • Published 10.10.2002 04:00:00
  • Last modified 03.04.2025 01:03:51

Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long ...