radar

ONE Sentinel

shield

CVE Tracker

212,655 total CVEs

Live vulnerability feed from the National Vulnerability Database

10.0

A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.

10.0

A Windows NT log file has an inappropriate maximum size or retention period.

10.0

A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.

4.9

The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.

10.0

The Logon box of a Windows NT system displays the name of the last user who logged in.

10.0

An event log in Windows NT has inappropriate access permissions.

10.0

A system-critical Windows NT registry key has inappropriate permissions.

7.5

A filter in a router or firewall allows unusual fragmented packets.

10.0

A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.

0.0

A network service is running on a nonstandard port.

10.0

A Windows NT file system is not NTFS.

10.0

There is a one-way or two-way trust relationship between Windows NT domains.

10.0

The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.

10.0

The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions.

10.0

A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.

4.6

A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.

10.0

A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.

10.0

A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.

10.0

Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.

10.0

A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.

10.0

rpc.admind in Solaris is not running in a secure mode.

10.0

A Sendmail alias allows input to be piped to a program.

10.0

An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.

10.0

IIS has the #exec function enabled for Server Side Include (SSI) files.

10.0

A system-critical Windows NT file or directory has inappropriate permissions.

Showing 211901-211925 of 212,655 CVEs