Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Internet Information Services
Total 92 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0150 1 Microsoft 2 Internet Information Server, Internet Information Services 2023-12-10 7.5 HIGH N/A
Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.
CVE-2000-0884 1 Microsoft 2 Internet Information Server, Internet Information Services 2023-12-10 7.5 HIGH N/A
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.
CVE-2003-0223 1 Microsoft 2 Internet Information Server, Internet Information Services 2023-12-10 6.8 MEDIUM N/A
Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.
CVE-2002-0869 1 Microsoft 2 Internet Information Server, Internet Information Services 2023-12-10 7.5 HIGH N/A
Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."
CVE-1999-0412 1 Microsoft 2 Internet Information Server, Internet Information Services 2023-12-10 7.5 HIGH N/A
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
CVE-2000-1104 1 Microsoft 2 Internet Information Server, Internet Information Services 2023-12-10 7.5 HIGH N/A
Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.
CVE-2001-0508 1 Microsoft 1 Internet Information Services 2023-12-10 5.0 MEDIUM N/A
Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.
CVE-2002-1180 1 Microsoft 1 Internet Information Services 2023-12-10 7.5 HIGH N/A
A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."
CVE-2000-0071 1 Microsoft 2 Internet Information Server, Internet Information Services 2023-12-10 5.0 MEDIUM N/A
IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.
CVE-2001-0902 1 Microsoft 1 Internet Information Services 2023-12-10 7.5 HIGH N/A
Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters.
CVE-2002-0422 1 Microsoft 1 Internet Information Services 2023-12-10 2.6 LOW N/A
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method, which leaks the IP in the Location server header.
CVE-2000-0246 1 Microsoft 6 Commercial Internet System, Internet Information Server, Internet Information Services and 3 more 2023-12-10 5.0 MEDIUM N/A
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.
CVE-2001-0507 1 Microsoft 1 Internet Information Services 2023-12-10 7.2 HIGH N/A
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.
CVE-1999-0233 1 Microsoft 1 Internet Information Services 2023-12-10 10.0 HIGH N/A
IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.
CVE-2002-0224 1 Microsoft 3 Internet Information Services, Sql Server, Windows 2000 2023-12-10 5.0 MEDIUM N/A
The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.
CVE-2002-1700 2 Macromedia, Microsoft 3 Coldfusion, Internet Information Services, Windows 2000 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.
CVE-2001-0506 1 Microsoft 2 Internet Information Server, Internet Information Services 2023-12-10 7.2 HIGH N/A
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.
CVE-1999-0281 1 Microsoft 2 Internet Information Server, Internet Information Services 2023-12-10 5.0 MEDIUM N/A
Denial of service in IIS using long URLs.
CVE-2000-0408 1 Microsoft 2 Internet Information Server, Internet Information Services 2023-12-10 5.0 MEDIUM N/A
IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.
CVE-2001-1186 1 Microsoft 1 Internet Information Services 2023-12-10 5.0 MEDIUM N/A
Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection.