Skip to main content

Vendor/product archive

microsoft / isa_server CVEs

Beta · best-effort

21 CVEs tagged to microsoft / isa_server5 Critical, 8 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2009-1135

Published Jul 15, 2009

Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers t…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4991

Published Sep 21, 2007

The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7027

Published Feb 23, 2007

Microsoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remote attackers to manipulate por…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-3652

Published Jul 18, 2006

Microsoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing "#" character. NOTE: as of 2…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1651

Published Apr 6, 2006

Microsoft ISA Server 2004 allows remote attackers to bypass certain filtering rules, including ones for (1) ICMP and (2) TCP, via IPv6 packets. NOTE: An established researcher ha…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1215

Published Jun 14, 2005

Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Le…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1216

Published Jun 14, 2005

Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) pre…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1907

Published May 31, 2005

The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amou…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0526

Published Aug 18, 2003

Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL contain…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0110

Published May 5, 2003

The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0011

Published Mar 24, 2003

Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denia…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1533

Published Dec 31, 2001

Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disput…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0546

Published Sep 20, 2001

Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion…

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0547

Published Sep 20, 2001

Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).

CVSS 2.1 · Low
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0658

Published Sep 20, 2001

Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0239

Published Jul 2, 2001

Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1