CVEs (107)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 4Commercial Internet System Internet Information ServerSite Server+1 moreApr 16, 2026 Aug 11, 1999 N/A· v4 N/A· v3 2.6 LOW· v2 Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. |
1Microsoft 4Data Access Components Index ServerInternet Information Server+1 moreApr 16, 2026 Jul 19, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jul 7, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for norma...Show more |
1Microsoft 1Internet Information Server Apr 16, 2026 Jul 6, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character. |
1Microsoft 3Internet Information Server Windows 2000Windows NtApr 16, 2026 Jun 16, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions. |
1Microsoft 1Internet Information Server Apr 16, 2026 May 12, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Denial of service in Windows NT IIS server using ..\.. |
1Microsoft 1Internet Information Server Apr 16, 2026 May 7, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. |
1Microsoft 1Internet Information Server Apr 16, 2026 May 7, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. |
1Microsoft 1Internet Information Server Apr 16, 2026 May 7, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. |
1Microsoft 1Internet Information Server Apr 16, 2026 May 7, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Feb 19, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. |
1Microsoft 1Internet Information Server Apr 16, 2026 Feb 11, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. |
1Microsoft 1Internet Information Server Apr 16, 2026 Feb 9, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 27, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 27, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jan 26, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 26, 1999 N/A· v4 N/A· v3 7.8 HIGH· v2 The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 24, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 14, 1999 N/A· v4 N/A· v3 2.1 LOW· v2 When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information...Show more |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 14, 1999 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands. |