← Back

Internet Information Services

internet_information_services

Vendor: Microsoft • 91 CVEs

CVEs (91)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
May 10, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulne...Show more
Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.Show less
1Microsoft
3Frontpage
Internet Information ServerInternet Information Services
Apr 16, 2026
May 6, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which gener...Show more
The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.Show less
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Apr 12, 2000
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.
1Microsoft
6Commercial Internet System
Internet Information ServerInternet Information Services+3 more
Apr 16, 2026
Mar 30, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC...Show more
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.Show less
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Jan 11, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Dec 31, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Feb 19, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Jan 26, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Jun 1, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service in IIS using long URLs.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.
1Microsoft
1Internet Information Services
Apr 16, 2026
Feb 25, 1996
N/A· v4
N/A· v3
10.0 HIGH· v2
IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.