Microsoft

Internet Information Services

91 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Exploit
  • EPSS 94.37%
  • Veröffentlicht 27.03.2017 02:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://...

  • EPSS 16.38%
  • Veröffentlicht 11.11.2014 22:55:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for domains within the "IP Address and Domain Restrictions" list, which makes it easier for remote attackers ...

Exploit
  • EPSS 8.55%
  • Veröffentlicht 23.04.2014 20:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a \n (newline) characte...

Exploit
  • EPSS 91.69%
  • Veröffentlicht 23.12.2010 18:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to execute arbitrary code or cause a den...

  • EPSS 10.3%
  • Veröffentlicht 15.09.2010 19:00:19
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in Microsoft Internet Information Services (IIS) 7.5, when FastCGI is enabled, allows remote attackers to execute arbitrary code via crafted headers in a request, aka "Request Header Buffer Overflow Vulnerability."

  • EPSS 86.63%
  • Veröffentlicht 15.09.2010 19:00:18
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS...

  • EPSS 10.06%
  • Veröffentlicht 29.12.2009 21:00:24
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications, allows remote attackers to create empty files with arbitrary extensions via a filename containing an initial extension followed ...

  • EPSS 58.58%
  • Veröffentlicht 29.12.2009 21:00:24
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) character to determine the file extension, which allows remote attackers to bypass intended extension restrictions of third-party upl...

  • EPSS 60.78%
  • Veröffentlicht 04.09.2009 10:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that re...

  • EPSS 92.34%
  • Veröffentlicht 10.06.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "I...