CVEs (107)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Internet Information Server Internet Information ServicesApr 29, 2026 Sep 15, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request...Show more |
1Microsoft 1Internet Information Server Apr 29, 2026 Jun 8, 2010 N/A· v4 N/A· v3 8.5 HIGH· v2 Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token chec...Show more |
Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted...Show more |
1Microsoft 1Internet Information Server Apr 23, 2026 Aug 31, 2009 N/A· v4 N/A· v3 9.0 HIGH· v2 Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards,...Show more |
1Microsoft 1Internet Information Server Apr 23, 2026 Feb 12, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 23, 2026 Feb 12, 2008 N/A· v4 N/A· v3 7.2 HIGH· v2 Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or W...Show more |
1Microsoft 1Internet Information Server Apr 23, 2026 May 30, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and mi...Show more |
1Microsoft 1Internet Information Server Apr 23, 2026 Jan 5, 2007 N/A· v4 N/A· v3 7.8 HIGH· v2 Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that...Show more |
1Microsoft 2Internet Information Server Internet Information ServicesApr 23, 2026 Dec 15, 2006 N/A· v4 N/A· v3 4.4 MEDIUM· v2 Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an...Show more |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jul 11, 2006 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP). |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Aug 23, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the requ...Show more |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Nov 3, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML...Show more |
2Avaya Microsoft5Definity One Media Server Internet Information ServerIp600 Media Servers+2 moreApr 16, 2026 Aug 6, 2004 N/A· v4 N/A· v3 7.2 HIGH· v2 Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jun 9, 2003 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a...Show more |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jun 9, 2003 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redi...Show more |
1Microsoft 3Exchange Server Internet Information ServerInternet Information ServicesApr 16, 2026 Dec 31, 2002 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerabili...Show more |
2Microsoft Symantec3Internet Information Server Internet Information ServicesNorton Internet SecurityApr 16, 2026 Dec 31, 2002 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Dec 31, 2002 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Nov 12, 2002 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1)...Show more |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Nov 12, 2002 N/A· v4 N/A· v3 7.5 HIGH· v2 Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquir...Show more |