CVEs (107)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Apr 12, 2000 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability. |
1Microsoft 6Commercial Internet System Internet Information ServerInternet Information Services+3 moreApr 16, 2026 Mar 30, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC...Show more |
1Microsoft 1Internet Information Server Apr 16, 2026 Mar 20, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the "Chunked Transfer Encoding Buffer Overflow Vulnerability." |
1Microsoft 1Internet Information Server Apr 16, 2026 Feb 15, 2000 N/A· v4 N/A· v3 2.1 LOW· v2 IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory. |
1Microsoft 1Internet Information Server Apr 16, 2026 Feb 2, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 26, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 21, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jan 11, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. |
1Microsoft 2Internet Information Server Visual InterdevApr 16, 2026 Dec 31, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authe...Show more |
1Microsoft 2Internet Information Server Site ServerApr 16, 2026 Dec 31, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files. |
1Microsoft 1Internet Information Server Apr 16, 2026 Dec 31, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability. |
1Microsoft 1Internet Information Server Apr 16, 2026 Dec 31, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters. |
1Microsoft 1Internet Information Server Apr 16, 2026 Dec 31, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time. |
1Microsoft 1Internet Information Server Apr 16, 2026 Dec 31, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Dec 31, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL. |
1Microsoft 3Internet Information Server Site ServerSite Server CommerceApr 16, 2026 Dec 21, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory...Show more |
1Microsoft 3Internet Information Server Site ServerSite Server CommerceApr 16, 2026 Dec 21, 1999 N/A· v4 N/A· v3 6.4 MEDIUM· v2 IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability. |
1Microsoft 2Commercial Internet System Internet Information ServerApr 16, 2026 Sep 23, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions. |
1Microsoft 1Internet Information Server Apr 16, 2026 Aug 19, 1999 N/A· v4 N/A· v3 7.1 HIGH· v2 When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". |
1Microsoft 3Commercial Internet System Internet Information ServerSite ServerApr 16, 2026 Aug 11, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. |