Vulnerabilities > Microsoft > Windows NT > 4.0

DATE CVE VULNERABILITY TITLE RISK
2003-05-12 CVE-2003-0112 Buffer Overflow vulnerability in Microsoft Windows Kernel Message Handling
Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.
local
low complexity
microsoft
4.6
2003-04-02 CVE-2002-1561 Denial of Service vulnerability in Microsoft Windows RPC Service
The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.
network
low complexity
microsoft
5.0
2003-03-24 CVE-2003-0010 Heap Overflow vulnerability in Microsoft Windows Script Engine JScript.DLL
Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.
network
low complexity
microsoft
7.5
2003-02-07 CVE-2003-0003 Buffer Overflow vulnerability in Microsoft Windows Locator Service
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
network
low complexity
microsoft
7.5
2002-12-31 CVE-2002-2073 Cross-Site Scripting vulnerability in Microsoft Site Server 3.0
Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp.
network
microsoft
4.3
2002-12-23 CVE-2002-1325 Information Disclosure vulnerability in Microsoft Java Virtual Machine user.dir Access
Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."
network
low complexity
microsoft
5.0
2002-12-23 CVE-2002-1260 Unspecified vulnerability in Microsoft products
The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet.
network
low complexity
microsoft
7.5
2002-12-23 CVE-2002-1258 Unspecified vulnerability in Microsoft products
Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.
network
low complexity
microsoft
5.0
2002-12-23 CVE-2002-1257 Unspecified vulnerability in Microsoft products
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.
network
low complexity
microsoft
critical
10.0
2002-12-11 CVE-2002-1183 Unspecified vulnerability in Microsoft Windows 98, Windows 98Se and Windows NT
Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).
network
low complexity
microsoft
7.5