Microsoft Internet Information Server vulnerabilities

103 known vulnerabilities affecting microsoft/internet_information_server.

Total CVEs
103
CISA KEV
0
Public exploits
38
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH34MEDIUM57LOW5

Vulnerabilities

Page 1 of 6
CVE-2010-1899MEDIUMCVSS 4.3PoCv6.02010-09-15
CVE-2010-1899 [MEDIUM] CWE-119 CVE-2010-1899: Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."
nvd
CVE-2010-1256HIGHCVSS 8.5v6.02010-06-08
CVE-2010-1256 [HIGH] CWE-94 CVE-2010-1256: Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentic Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, aka "IIS Authentication Memory Corruption Vulnerability."
nvd
CVE-2003-1582LOWCVSS 2.6v6.02010-02-05
CVE-2003-1582 [LOW] CWE-79 CVE-2003-1582: Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addr Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
nvd
CVE-2009-3023CRITICALCVSS 9.0PoC≥ 5.0, ≤ 6.02009-08-31
CVE-2009-3023 [CRITICAL] CWE-120 CVE-2009-3023: Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability."
nvd
CVE-2008-0075CRITICALCVSS 10.0v6.02008-02-12
CVE-2008-0075 [CRITICAL] CWE-94 CVE-2008-0075: Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows re Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages.
nvd
CVE-2008-0074HIGHCVSS 7.2v6.02008-02-12
CVE-2008-0074 [HIGH] CWE-264 CVE-2008-0074: Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows lo Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders.
nvd
CVE-2007-2897HIGHCVSS 7.5v6.02007-05-30
CVE-2007-2897 [HIGH] CVE-2007-2897: Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of servi Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and might allow attackers with physical access to execute arbitrary code after connecting a data stream to a device COM port; via requests for a URI
nvd
CVE-2006-6579MEDIUMCVSS 4.4≤ 5.0v3.0+1 more2006-12-15
CVE-2006-6579 [MEDIUM] CVE-2006-6579: Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WIN Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an ASP shell that has write access by IWAM_machine and read access by IUSR_Machine.
nvd
CVE-2006-0026MEDIUMCVSS 6.5PoCv6.02006-07-11
CVE-2006-0026 [MEDIUM] CVE-2006-0026: Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).
nvd
CVE-2005-2678MEDIUMCVSS 5.0v6.02005-08-23
CVE-2005-2678 [MEDIUM] CVE-2005-2678: Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.
nvd
CVE-2003-0718MEDIUMCVSS 5.0PoCv6.02004-11-03
CVE-2003-0718 [MEDIUM] CVE-2003-0718: The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote a The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.
nvd
CVE-2004-0205HIGHCVSS 7.2v4.02004-08-06
CVE-2004-0205 [HIGH] CVE-2004-0205: Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arb Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.
nvd
CVE-2003-0225MEDIUMCVSS 5.0v4.02003-06-09
CVE-2003-0225 [MEDIUM] CVE-2003-0225: The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.
nvd
CVE-2003-0223MEDIUMCVSS 6.8v4.02003-06-09
CVE-2003-0223 [MEDIUM] CVE-2003-0223: Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsof Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.
nvd
CVE-2002-1694MEDIUMCVSS 5.0v4.02002-12-31
CVE-2002-1694 [MEDIUM] CVE-2002-1694: Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_ Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running.
nvd
CVE-2002-1695MEDIUMCVSS 5.0v4.02002-12-31
CVE-2002-1695 [MEDIUM] CVE-2002-1695: Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running.
nvd
CVE-2002-1790MEDIUMCVSS 5.0PoCv4.02002-12-31
CVE-2002-1790 [MEDIUM] CVE-2002-1790: The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attacker The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682.
nvd
CVE-2002-0869HIGHCVSS 7.5v4.02002-11-12
CVE-2002-0869 [HIGH] CVE-2002-0869: Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."
nvd
CVE-2002-1181MEDIUMCVSS 6.8v4.02002-11-12
CVE-2002-1181 [MEDIUM] CVE-2002-1181: Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft In Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.
nvd
CVE-2002-0419MEDIUMCVSS 5.0PoCv4.02002-08-12
CVE-2002-0419 [MEDIUM] CWE-200 CVE-2002-0419: Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive inform Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NA
nvd