CVEs (91)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1Internet Information Services Apr 21, 2026 Mar 27, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long heade...Show more |
1Microsoft 1Internet Information Services May 6, 2026 Nov 11, 2014 N/A· v4 N/A· v3 5.1 MEDIUM· v2 The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for domains within the "IP Address and Domain Restrictions" list, which makes i...Show more |
1Microsoft 1Internet Information Services May 6, 2026 Apr 23, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variabl...Show more |
1Microsoft 1Internet Information Services Apr 29, 2026 Dec 23, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to execute...Show more |
1Microsoft 1Internet Information Services Apr 29, 2026 Sep 15, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Buffer overflow in Microsoft Internet Information Services (IIS) 7.5, when FastCGI is enabled, allows remote attackers to execute arbitrary code via crafted headers in a request, aka "Request Header Buffer Overflow Vulne...Show more |
1Microsoft 2Internet Information Server Internet Information ServicesApr 29, 2026 Sep 15, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request...Show more |
1Microsoft 1Internet Information Services Apr 23, 2026 Dec 29, 2009 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications, allows remote attackers to create empty files with arbitrary extensions via a filename containing...Show more |
1Microsoft 1Internet Information Services Apr 23, 2026 Dec 29, 2009 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) character to determine the file extension, which allows remote attackers to bypass intended extension r...Show more |
1Microsoft 1Internet Information Services Apr 23, 2026 Sep 4, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command...Show more |
1Microsoft 1Internet Information Services Apr 23, 2026 Jun 10, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via...Show more |
1Microsoft 1Internet Information Services Apr 23, 2026 Jun 10, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicod...Show more |
1Microsoft 1Internet Information Services May 28, 2026 Jan 15, 2009 N/A· v4 7.5 HIGH· v3 5.8 MEDIUM· v2 The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and...Show more |
1Microsoft 1Internet Information Services Apr 23, 2026 Jan 15, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection. |
1Microsoft 1Internet Information Services Apr 23, 2026 Oct 15, 2008 N/A· v4 N/A· v3 9.0 HIGH· v2 Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allo...Show more |
1Microsoft 1Internet Information Services Apr 23, 2026 Sep 29, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set a password via a string argument to the SetPassword method. NOTE: this issue could not be reproduce...Show more |
1Microsoft 1Internet Information Services Apr 23, 2026 Sep 29, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 A certain ActiveX control in adsiis.dll in Microsoft Internet Information Services (IIS) allows remote attackers to cause a denial of service (browser crash) via a long string in the second argument to the GetObject meth...Show more |
1Microsoft 2Internet Information Server Internet Information ServicesApr 23, 2026 Feb 12, 2008 N/A· v4 N/A· v3 7.2 HIGH· v2 Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or W...Show more |
1Microsoft 1Internet Information Services Apr 23, 2026 May 22, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentic...Show more |
1Microsoft 2Internet Information Server Internet Information ServicesApr 23, 2026 Dec 15, 2006 N/A· v4 N/A· v3 4.4 MEDIUM· v2 Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an...Show more |
1Microsoft 1Internet Information Services Apr 23, 2026 Dec 15, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that exe...Show more |