- EPSS 18.09%
- Veröffentlicht 31.12.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.
- EPSS 15.53%
- Veröffentlicht 31.12.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.
CVE-1999-1233
- EPSS 10.31%
- Veröffentlicht 31.12.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.
- EPSS 35.59%
- Veröffentlicht 31.12.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.
CVE-1999-1591
- EPSS 15.94%
- Veröffentlicht 31.12.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as dem...
CVE-2000-0024
- EPSS 12.05%
- Veröffentlicht 21.12.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.
- EPSS 46.05%
- Veröffentlicht 21.12.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.
CVE-1999-0777
- EPSS 1.34%
- Veröffentlicht 23.09.1999 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.
CVE-1999-0725
- EPSS 38.53%
- Veröffentlicht 19.08.1999 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".
CVE-1999-0861
- EPSS 5.46%
- Veröffentlicht 11.08.1999 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.