Microsoft Internet Information Services vulnerabilities
88 known vulnerabilities affecting microsoft/internet_information_services.
Total CVEs
88
CISA KEV
1
actively exploited
Public exploits
38
Exploited in wild
7
Severity breakdown
CRITICAL7HIGH31MEDIUM47LOW3
Vulnerabilities
Page 3 of 5
CVE-2002-0149P3HIGHCVSS 7.5v5.02002-04-22
CVE-2002-0149 [HIGH] CVE-2002-0149: Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers
Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.
nvd
CVE-2003-0226P4MEDIUMCVSS 5.0PoCv5.02003-06-09
CVE-2003-0226 [MEDIUM] CVE-2003-0226: Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial
Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.
nvd
CVE-2001-1186P4MEDIUMCVSS 5.0PoCv5.02001-12-11
CVE-2001-1186 [MEDIUM] CVE-2001-1186: Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a co
Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection.
nvd
CVE-2000-0408P4MEDIUMCVSS 5.0PoCv5.02000-05-11
CVE-2000-0408 [MEDIUM] CVE-2000-0408: IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that ap
IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.
nvd
CVE-2002-0150P3HIGHCVSS 7.5v5.02002-04-22
CVE-2002-0150 [HIGH] CVE-2002-0150: Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to sp
Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.
nvd
CVE-2000-0413P4MEDIUMCVSS 5.0PoCv5.02000-05-06
CVE-2000-0413 [MEDIUM] CVE-2000-0413: The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers
The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.
nvd
CVE-2002-1700P4MEDIUMCVSS 4.3PoCv5.02002-12-31
CVE-2002-1700 [MEDIUM] CWE-79 CVE-2002-1700: Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX
Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.
nvd
CVE-2002-0364P3HIGHCVSS 7.5v5.02002-07-03
CVE-2002-0364 [HIGH] CVE-2002-0364: Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to ex
Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."
nvd
CVE-2014-4078P3MEDIUMCVSS 5.1v8.0v8.52014-11-11
CVE-2014-4078 [MEDIUM] CWE-264 CVE-2014-4078: The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not proper
The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for domains within the "IP Address and Domain Restrictions" list, which makes it easier for remote attackers to bypass an intended rule set via an HTTP request, aka "IIS Security Feature Bypass Vulnerability."
nvd
CVE-2002-0869P3HIGHCVSS 7.5v5.02002-11-12
CVE-2002-0869 [HIGH] CVE-2002-0869: Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server
Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."
nvd
CVE-2011-5279P3MEDIUMCVSS 5.0v4.0v5.02014-04-23
CVE-2011-5279 [MEDIUM] CVE-2011-5279: CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (I
CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a \n (newline) character in an HTTP header.
nvd
CVE-2003-0224P3CRITICALCVSS 10.0v5.02003-06-09
CVE-2003-0224 [CRITICAL] CVE-2003-0224: Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local user
Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."
nvd
CVE-2006-6578P3HIGHCVSS 7.5v5.12006-12-15
CVE-2006-6578 [HIGH] CVE-2006-6578: Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EX
Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments, as demonstrated using win.com when it is in a web directory with certain permissions.
nvd
CVE-2009-4445P4MEDIUMCVSS 6.0≤ 6.02009-12-29
CVE-2009-4445 [MEDIUM] CWE-20 CVE-2009-4445: Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party
Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications, allows remote attackers to create empty files with arbitrary extensions via a filename containing an initial extension followed by a : (colon) and a safe extension, as demonstrated by an upload of a .asp:.jpg file that results in cr
nvd
CVE-2000-0970P4HIGHCVSS 7.5v5.02000-12-19
CVE-2000-0970 [HIGH] CVE-2000-0970: IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, whi
IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.
nvd
CVE-2002-0071P4HIGHCVSS 7.5v5.02002-04-22
CVE-2002-0071 [HIGH] CVE-2002-0071: Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information
Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.
nvd
CVE-2008-0074P4HIGHCVSS 7.2v5.02008-02-12
CVE-2008-0074 [HIGH] CWE-264 CVE-2008-0074: Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows lo
Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders.
nvd
CVE-2002-1745P4HIGHCVSS 7.5v5.02002-12-31
CVE-2002-1745 [HIGH] CWE-193 CVE-2002-1745: Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to v
Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc, such as .aspx files.
nvd
CVE-2005-2089P4MEDIUMCVSS 4.3v5.0v6.02005-07-05
CVE-2005-2089 [MEDIUM] CWE-444 CVE-2005-2089: Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application fi
Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes IIS to incorrectly handle and forward the body of the request in a way that causes the receiving ser
nvd
CVE-2002-0072P4MEDIUMCVSS 5.0v5.02002-04-22
CVE-2002-0072 [MEDIUM] CVE-2002-0072: The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Serv
The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote attackers to cause a denial of service (crash) when the URL parser accesses a null pointer.
nvd