← Back

Internet Information Server

internet_information_server

Vendor: Microsoft • 107 CVEs

CVEs (107)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
4Commercial Internet System
Internet Information ServerSite Server+1 more
Apr 16, 2026
Aug 11, 1999
N/A· v4
N/A· v3
2.6 LOW· v2
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
1Microsoft
4Data Access Components
Index ServerInternet Information Server+1 more
Apr 16, 2026
Jul 19, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
1Microsoft
1Internet Information Server
Apr 16, 2026
Jul 7, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for norma...Show more
IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.Show less
1Microsoft
1Internet Information Server
Apr 16, 2026
Jul 6, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.
1Microsoft
3Internet Information Server
Windows 2000Windows Nt
Apr 16, 2026
Jun 16, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
1Microsoft
1Internet Information Server
Apr 16, 2026
May 12, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service in Windows NT IIS server using ..\..
1Microsoft
1Internet Information Server
Apr 16, 2026
May 7, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
1Microsoft
1Internet Information Server
Apr 16, 2026
May 7, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
1Microsoft
1Internet Information Server
Apr 16, 2026
May 7, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
1Microsoft
1Internet Information Server
Apr 16, 2026
May 7, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Feb 19, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
1Microsoft
1Internet Information Server
Apr 16, 2026
Feb 11, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.
1Microsoft
1Internet Information Server
Apr 16, 2026
Feb 9, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.
1Microsoft
1Internet Information Server
Apr 16, 2026
Jan 27, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.
1Microsoft
1Internet Information Server
Apr 16, 2026
Jan 27, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Jan 26, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
1Microsoft
1Internet Information Server
Apr 16, 2026
Jan 26, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.
1Microsoft
1Internet Information Server
Apr 16, 2026
Jan 24, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.
1Microsoft
1Internet Information Server
Apr 16, 2026
Jan 14, 1999
N/A· v4
N/A· v3
2.1 LOW· v2
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information...Show more
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.Show less
1Microsoft
1Internet Information Server
Apr 16, 2026
Jan 14, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.