Microsoft

Internet Information Server

107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 86.63%
  • Veröffentlicht 15.09.2010 19:00:18
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS...

  • EPSS 33.55%
  • Veröffentlicht 08.06.2010 20:30:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corr...

Exploit
  • EPSS 4.96%
  • Veröffentlicht 05.02.2010 22:30:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated...

Exploit
  • EPSS 77.22%
  • Veröffentlicht 31.08.2009 20:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, ...

  • EPSS 2.03%
  • Veröffentlicht 12.02.2008 21:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders.

  • EPSS 72.5%
  • Veröffentlicht 12.02.2008 21:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages.

  • EPSS 53.48%
  • Veröffentlicht 30.05.2007 10:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and might allow attackers with physi...

  • EPSS 42.16%
  • Veröffentlicht 05.01.2007 18:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of ...

  • EPSS 0.19%
  • Veröffentlicht 15.12.2006 19:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Microsoft Windows XP has weak permissions (FILE_WRITE_DATA and FILE_READ_DATA for Everyone) for %WINDIR%\pchealth\ERRORREP\QHEADLES, which allows local users to write and read files in this folder, as demonstrated by an ASP shell that has write acces...

  • EPSS 90.12%
  • Veröffentlicht 11.07.2006 22:05:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).