| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A Unix account with a name other than "root" has UID 0, i.e. root privileges. |
| A system-critical Windows NT file or directory has inappropriate permissions. |
| IIS has the #exec function enabled for Server Side Include (SSI) files. |
| The registry in Windows NT can be accessed remotely by users who are not administrators. |
| An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled. |
| A Sendmail alias allows input to be piped to a program. |
| An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities. |
| rpc.admind in Solaris is not running in a secure mode. |
| A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file. |
| .reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks. |
| A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking. |
| A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories. |
| A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. |
| There is a one-way or two-way trust relationship between Windows NT domains. |
| A Windows NT administrator account has the default name of Administrator. |
| A filter in a router or firewall allows unusual fragmented packets. |
| A system does not present an appropriate legal message or warning to a user who is accessing it. |
| The Logon box of a Windows NT system displays the name of the last user who logged in. |
| The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. |
| A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive. |