Skip to main content

Vendor/product archive

microsoft / internet_information_services CVEs

Beta · best-effort

90 CVEs tagged to microsoft / internet_information_services7 Critical, 30 High, 50 Medium, 3 Low, 0 Unrated.

CVE-2014-4078

Published Nov 11, 2014

The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for domains within the "IP Address and…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3972

Published Dec 23, 2010

Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and II…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-2730

Published Sep 15, 2010

Buffer overflow in Microsoft Internet Information Services (IIS) 7.5, when FastCGI is enabled, allows remote attackers to execute arbitrary code via crafted headers in a request,…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4445

Published Dec 29, 2009

Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications, allows remote attackers to create empty files with arbitr…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4444

Published Dec 29, 2009

Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) character to determine the file extension, which allows remote…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2521

Published Sep 4, 2009

Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1567

Published Jan 15, 2009

The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1566

Published Jan 15, 2009

Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4301

Published Sep 29, 2008

A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set a password via a string argument to the SetPassword method.…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4300

Published Sep 29, 2008

A certain ActiveX control in adsiis.dll in Microsoft Internet Information Services (IIS) allows remote attackers to cause a denial of service (browser crash) via a long string in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2815

Published May 22, 2007

The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote att…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6578

Published Dec 15, 2006

Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary command…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 90 CVEsPage 1 of 4