| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. |
| Windows NT RSHSVC program allows remote users to execute arbitrary commands. |
| IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. |
| Buffer overflow in War FTP allows remote execution of commands. |
| Bonk variation of teardrop IP fragmentation denial of service. |
| Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made. |
| Denial of service in Windows NT DNS servers by flooding port 53 with too many characters. |
| In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL. |
| Remote command execution in Microsoft Internet Explorer using .lnk and .url files. |
| Denial of service in IIS using long URLs. |
| Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. |
| Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection. |
| The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets. |
| The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL. |
| Denial of service through Winpopup using large user names. |
| All records in a WINS database can be deleted through SNMP for a denial of service. |
| Buffer overflow in Internet Explorer 4.0(1). |
| Buffer overflow in NetMeeting allows denial of service and remote command execution. |
| NT users can gain debug-level access on a system process using the Sechole exploit. |
| Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character. |