| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file. |
| Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. |
| A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts. |
| .reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks. |
| A Sendmail alias allows input to be piped to a program. |
| A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. |
| A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. |
| A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. |
| The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions. |
| The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. |
| A network service is running on a nonstandard port. |
| There is a one-way or two-way trust relationship between Windows NT domains. |
| A filter in a router or firewall allows unusual fragmented packets. |
| A system-critical Windows NT registry key has inappropriate permissions. |
| A system does not present an appropriate legal message or warning to a user who is accessing it. |
| An event log in Windows NT has inappropriate access permissions. |
| The Logon box of a Windows NT system displays the name of the last user who logged in. |
| The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. |
| A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive. |
| A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded. |