← Back

Internet Information Server

internet_information_server

Vendor: Microsoft • 107 CVEs

CVEs (107)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Internet Information Server
Apr 16, 2026
Jan 1, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
5C2net
HpMicrosoft+2 more
13Certificate Server
Collabra ServerDirectory Server+10 more
Apr 16, 2026
Jun 26, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Information from SSL-encrypted sessions via PKCS #1.
1Microsoft
2Internet Information Server
Windows Nt
Apr 16, 2026
Jun 1, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
2Microsoft
Netscape
5Enterprise Server
Fasttrack ServerFrontpage+2 more
Apr 16, 2026
Feb 6, 1998
N/A· v4
7.0 HIGH· v3
5.0 MEDIUM· v2
Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
1Microsoft
1Internet Information Server
Apr 16, 2026
Sep 1, 1997
N/A· v4
N/A· v3
6.4 MEDIUM· v2
IIS newdsn.exe CGI script allows remote users to overwrite files.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Jun 1, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service in IIS using long URLs.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.