Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Internet_information_services
(Microsoft)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 90 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2002-04-22 | CVE-2002-0072 | The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote attackers to cause a denial of service (crash) when the URL parser accesses a null pointer. | Internet_information_server, Internet_information_services | N/A | ||
2002-04-22 | CVE-2002-0074 | Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session. | Internet_information_server, Internet_information_services | N/A | ||
2006-12-15 | CVE-2006-6579 | Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an ASP shell that has write access by IWAM_machine and read access by IUSR_Machine. | Internet_information_server, Internet_information_services | N/A | ||
2006-07-11 | CVE-2006-0026 | Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP). | Internet_information_server, Internet_information_services | N/A | ||
2005-08-23 | CVE-2005-2678 | Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost. | Internet_information_server, Internet_information_services | N/A | ||
2004-11-03 | CVE-2003-0718 | The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes. | Internet_information_server, Internet_information_services | N/A | ||
2003-06-09 | CVE-2003-0226 | Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled. | Internet_information_services | N/A | ||
2003-06-09 | CVE-2003-0223 | Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message. | Internet_information_server, Internet_information_services | N/A | ||
2002-12-31 | CVE-2002-1908 | Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters. | Internet_information_services | N/A | ||
2002-11-12 | CVE-2002-1182 | IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned. | Internet_information_services | N/A |