VYPR

Commercial Internet System

Sign in to watch

by Microsoft

CVEs (6)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2000-02460.100.84Mar 30, 2000IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.
CVE-1999-08670.050.19Aug 11, 1999Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
CVE-1999-09100.020.20Sep 10, 1999Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.
CVE-2000-00530.010.14Jan 4, 2000Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.
CVE-1999-07770.000.01Sep 23, 1999IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.
CVE-1999-08610.000.05Aug 11, 1999Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.