CVE-1999-0450high · CVSS 7.5 — In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
CVE-2000-0071medium · CVSS 5.0 — IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensi
CVE-2000-0246medium · CVSS 5.0 — IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote at
CVE-2000-0258high · CVSS 7.5 — IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the
CVE-2000-0413medium · CVSS 5.0 — The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML,
CVE-2000-0304medium · CVSS 5.0 — Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malform
CVE-2000-0408medium · CVSS 5.0 — IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file
CVE-2000-0457high · CVSS 7.5 — ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spac
CVE-2000-0649low · CVSS 2.6 — IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by
CVE-2000-0631medium · CVSS 5.0 — An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing
CVE-2000-0630medium · CVSS 5.0 — IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment
CVE-2000-0746high · CVSS 7.5 — Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site oper
CVE-2000-0770medium · CVSS 6.4 — IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, whi
CVE-2000-0778medium · CVSS 5.0 — IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header,
CVE-2000-0884high · CVSS 7.5 — IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed UR
CVE-2000-0886high · CVSS 7.5 — IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with ope
CVE-2000-0951medium · CVSS 5.0 — A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web ro
CVE-2000-0970high · CVSS 7.5 — IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijac
CVE-2000-1104high · CVSS 7.5 — Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site o
CVE-2001-0004medium · CVSS 5.0 — IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested
CVE-2001-0096medium · CVSS 5.0 — FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Ma
CVE-2001-0146medium · CVSS 5.0 — IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a se
CVE-2001-0151medium · CVSS 5.0 — IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.
CVE-2001-1243medium · CVSS 5.0 — Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) vi
CVE-2001-0506high · CVSS 7.2 — Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for
CVE-2001-0507high · CVSS 7.2 — IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse fi
CVE-2001-0508medium · CVSS 5.0 — Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.
CVE-2001-0544low · CVSS 2.1 — IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type h
CVE-2001-0902high · CVSS 7.5 — Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed charac
CVE-2001-1186medium · CVSS 5.0 — Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than t
CVE-2002-0071high · CVSS 7.5 — Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attacke
CVE-2002-0072medium · CVSS 5.0 — The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not prop
CVE-2002-0073medium · CVSS 5.0 — The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial
CVE-2002-0074high · CVSS 7.5 — Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attacke
CVE-2002-0075high · CVSS 7.5 — Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary scrip
CVE-2002-0079high · CVSS 7.5 — Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attac
CVE-2002-0147high · CVSS 7.5 — Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a
CVE-2002-0148high · CVSS 7.5 — Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script
CVE-2002-0149high · CVSS 7.5 — Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibl
CVE-2002-0150high · CVSS 7.5 — Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers an
CVE-2002-0224medium · CVSS 5.0 — The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through S
CVE-2002-0364high · CVSS 7.5 — Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing
CVE-2002-0419medium · CVSS 5.0 — Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force
CVE-2002-0422low · CVSS 2.6 — IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by
CVE-2002-0869high · CVSS 7.5 — Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote att
CVE-2002-1180high · CVSS 7.5 — A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files
CVE-2002-1181medium · CVSS 6.8 — Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 thro
CVE-2002-1182medium · CVSS 5.0 — IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memo
CVE-2002-1694medium · CVSS 5.0 — Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow rem
CVE-2002-1695medium · CVSS 5.0 — Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to m