CVEs (91)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 May 10, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulne...Show more |
1Microsoft 3Frontpage Internet Information ServerInternet Information ServicesApr 16, 2026 May 6, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which gener...Show more |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Apr 12, 2000 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability. |
1Microsoft 6Commercial Internet System Internet Information ServerInternet Information Services+3 moreApr 16, 2026 Mar 30, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC...Show more |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jan 11, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Dec 31, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Feb 19, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jan 26, 1999 N/A· v4 N/A· v3 7.5 HIGH· v2 In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jun 1, 1997 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Denial of service in IIS using long URLs. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Jan 1, 1997 N/A· v4 N/A· v3 7.5 HIGH· v2 IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. |
1Microsoft 1Internet Information Services Apr 16, 2026 Feb 25, 1996 N/A· v4 N/A· v3 10.0 HIGH· v2 IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. |