VYPR
Unrated severityNVD Advisory· Published Jul 7, 1999· Updated Jun 16, 2026

CVE-1999-1537

CVE-1999-1537

Description

IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:microsoft:internet_information_server:3.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:internet_information_server:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_information_server:4.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.