cbcvebase.

Microsoft Internet Information Server vulnerabilities

103 known vulnerabilities affecting microsoft/internet_information_server.

Total CVEs
103
CISA KEV
0
Public exploits
38
Exploited in wild
6
Severity breakdown
CRITICAL7HIGH34MEDIUM57LOW5

Vulnerabilities

Page 5 of 6
CVE-2000-0746P4HIGHCVSS 7.5v4.02000-10-20
CVE-2000-0746 [HIGH] CVE-2000-0746: Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attack Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross
nvd
CVE-1999-1478P4MEDIUMCVSS 5.0v3.0v4.01999-07-06
CVE-1999-1478 [MEDIUM] CVE-1999-1478: The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any s The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.
nvd
CVE-2000-1090P4MEDIUMCVSS 5.0v4.0v5.02001-02-12
CVE-2000-1090 [MEDIUM] CVE-2000-1090: Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for pars Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.
nvd
CVE-2000-0631P4MEDIUMCVSS 5.0v3.0v4.02000-07-14
CVE-2000-0631 [MEDIUM] CVE-2000-0631: An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability.
nvd
CVE-2000-0858P4MEDIUMCVSS 5.0v4.02000-11-14
CVE-2000-0858 [MEDIUM] CVE-2000-0858: Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in II Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability.
nvd
CVE-2001-0545P4MEDIUMCVSS 5.0v4.02001-10-30
CVE-2001-0545 [MEDIUM] CVE-2001-0545: IIS 4.0 with URL redirection enabled allows remote attackers to cause a denial of service (crash) vi IIS 4.0 with URL redirection enabled allows remote attackers to cause a denial of service (crash) via a malformed request that specifies a length that is different than the actual length.
nvd
CVE-1999-1148P4MEDIUMCVSS 5.0≤ 4.01999-12-31
CVE-1999-1148 [MEDIUM] CVE-1999-1148: FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource ex FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.
nvd
CVE-1999-0348P4MEDIUMCVSS 5.0v4.01999-01-27
CVE-1999-0348 [MEDIUM] CWE-200 CVE-1999-0348: IIS ASP caching problem releases sensitive information when two virtual servers share the same physi IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.
nvd
CVE-2000-0226P4MEDIUMCVSS 5.0v4.02000-03-20
CVE-2000-0226 [MEDIUM] CVE-2000-0226: IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the "Chunked Transfer Encoding Buffer Overflow Vulnerability."
nvd
CVE-1999-1035P4MEDIUMCVSS 5.0v3.0v4.01999-12-31
CVE-1999-1035 [MEDIUM] CVE-1999-1035: IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a m IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.
nvd
CVE-2000-1104P4HIGHCVSS 7.5v4.02001-01-09
CVE-2000-1104 [HIGH] CVE-2000-1104: Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE- Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.
nvd
CVE-1999-1223P4MEDIUMCVSS 5.0v3.01999-12-31
CVE-1999-1223 [MEDIUM] CVE-1999-1223: IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which t IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.
nvd
CVE-2002-1695P4MEDIUMCVSS 5.0v4.02002-12-31
CVE-2002-1695 [MEDIUM] CVE-2002-1695: Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running.
nvd
CVE-2003-0223P4MEDIUMCVSS 6.8v4.02003-06-09
CVE-2003-0223 [MEDIUM] CVE-2003-0223: Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsof Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.
nvd
CVE-1999-1537P4MEDIUMCVSS 5.0v3.0v4.01999-07-07
CVE-1999-1537 [MEDIUM] CVE-1999-1537: IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.
nvd
CVE-1999-0007P4MEDIUMCVSS 5.0v3.0v4.01998-06-26
CVE-1999-0007 [MEDIUM] CWE-327 CVE-1999-0007: Information from SSL-encrypted sessions via PKCS #1. Information from SSL-encrypted sessions via PKCS #1.
nvd
CVE-1999-1544P4MEDIUMCVSS 5.0v3.0v4.01999-01-24
CVE-1999-1544 [MEDIUM] CVE-1999-1544: Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attacke Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.
nvd
CVE-2001-0096P4MEDIUMCVSS 5.0v4.02001-02-12
CVE-2001-0096 [MEDIUM] CVE-2001-0096: FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of s FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.
nvd
CVE-2002-1694P4MEDIUMCVSS 5.0v4.02002-12-31
CVE-2002-1694 [MEDIUM] CVE-2002-1694: Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_ Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running.
nvd
CVE-2001-0337P4MEDIUMCVSS 5.0≤ 5.02001-06-27
CVE-2001-0337 [MEDIUM] CVE-2001-0337: The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which al The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.
nvd
Microsoft Internet Information Server vulnerabilities | cvebase