VYPR

IIS

by Microsoft

CVEs (64)

  • CVE-2001-0544Oct 30, 2001
    risk 0.00cvss epss 0.02

    IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type table.

  • CVE-2001-0337Jun 27, 2001
    risk 0.00cvss epss 0.05

    The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.

  • CVE-2000-1104Jan 9, 2001
    risk 0.00cvss epss 0.06

    Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The…

  • CVE-1999-1233Dec 31, 1999
    risk 0.00cvss epss 0.05

    IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.

Page 4 of 4