VYPR

Internet Information Server

by Microsoft

CVEs (154)

  • CVE-2003-0227Jun 9, 2003
    risk 0.06cvss epss 0.34

    The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute…

  • CVE-2002-0422Aug 12, 2002
    risk 0.06cvss epss 0.42

    IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response,…

  • CVE-2002-0419Aug 12, 2002
    risk 0.06cvss epss 0.38

    Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic…

  • CVE-2000-0951Dec 19, 2000
    risk 0.06cvss epss 0.44

    A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.

  • CVE-2000-0408May 11, 2000
    risk 0.06cvss epss 0.56

    IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.

  • CVE-2000-0413May 6, 2000
    risk 0.06cvss epss 0.42

    The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.

  • CVE-1999-0154Dec 31, 1999
    risk 0.06cvss epss 0.40

    IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.

  • CVE-2010-2731Sep 15, 2010
    risk 0.05cvss epss 0.31

    Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based Basic Authentication is enabled, allows remote attackers to bypass intended access restrictions and execute ASP files via a crafted request, aka "Directory…

  • CVE-2009-4444Dec 29, 2009
    risk 0.05cvss epss 0.64

    Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) character to determine the file extension, which allows remote attackers to bypass intended extension restrictions of third-party upload applications via a…

  • CVE-2003-1566Jan 15, 2009
    risk 0.05cvss epss 0.28

    Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.

  • CVE-2008-0075Feb 12, 2008
    risk 0.05cvss epss 0.57

    Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages.

  • CVE-2002-1790Dec 31, 2002
    risk 0.05cvss epss 0.34

    The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682.

  • CVE-2001-1186Dec 11, 2001
    risk 0.05cvss epss 0.35

    Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection.

  • CVE-2000-0457May 11, 2000
    risk 0.05cvss epss 0.51

    ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.

  • CVE-1999-0725Aug 19, 1999
    risk 0.05cvss epss 0.25

    When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".

  • CVE-1999-0867Aug 11, 1999
    risk 0.05cvss epss 0.22

    Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.

  • CVE-1999-1375Feb 11, 1999
    risk 0.05cvss epss 0.31

    FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.

  • CVE-1999-1538Jan 14, 1999
    risk 0.05cvss epss 0.25

    When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.

  • CVE-1999-0448Jan 1, 1999
    risk 0.05cvss epss 0.25

    IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.

  • CVE-2008-1446Oct 15, 2008
    risk 0.04cvss epss 0.46

    Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via…

Page 3 of 8