Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)12%—Microsoft Commercial Internet SystemMicrosoft Internet Information Server23/9/199916/6/2026
IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.
ModificadaAlta (7.1)25%💥 ExploitMicrosoft Internet Information Server19/8/199916/6/2026
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".
ModificadaBaja (2.6)3.2%—Microsoft Commercial Internet SystemMicrosoft Internet Information ServerMicrosoft Site ServerMicrosoft Site Server Commerce11/8/199916/6/2026
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
ModificadaMedia (5)22%💥 ExploitMicrosoft Commercial Internet SystemMicrosoft Internet Information ServerMicrosoft Site Server11/8/199916/6/2026
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
ModificadaAlta (10)77%💥 ExploitMicrosoft Data Access ComponentsMicrosoft Index ServerMicrosoft Internet Information ServerMicrosoft Site Server19/7/199916/6/2026
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
ModificadaMedia (5)8.5%—Microsoft Internet Information Server7/7/199916/6/2026
IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.
ModificadaMedia (5)18%—Microsoft Internet Information Server6/7/199916/6/2026
The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.
ModificadaAlta (10)75%💥 ExploitMicrosoft Internet Information ServerMicrosoft Windows 2000Microsoft Windows NT16/6/199916/6/2026
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
ModificadaMedia (5)5.9%—Microsoft Internet Information Server12/5/199916/6/2026
Denial of service in Windows NT IIS server using ..\..
ModificadaMedia (5)45%💥 ExploitMicrosoft Internet Information Server7/5/199916/6/2026
The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
ModificadaMedia (5)28%—Microsoft Internet Information Server7/5/199916/6/2026
The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
ModificadaMedia (5)29%—Microsoft Internet Information Server7/5/199916/6/2026
The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
ModificadaMedia (5)29%—Microsoft Internet Information Server7/5/199916/6/2026
The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
ModificadaAlta (7.5)10%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services19/2/199916/6/2026
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
ModificadaMedia (5)31%💥 ExploitMicrosoft Internet Information Server11/2/199916/6/2026
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.
ModificadaAlta (10)5.1%—Microsoft Internet Information Server9/2/199916/6/2026
By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.
ModificadaAlta (7.5)18%—Microsoft Internet Information Server27/1/199916/6/2026
A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.
ModificadaMedia (5)11%—Microsoft Internet Information Server27/1/199916/6/2026
IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.
ModificadaAlta (7.5)19%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services26/1/199916/6/2026
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
ModificadaAlta (7.8)49%—Microsoft Internet Information Server26/1/199916/6/2026
The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.
ModificadaMedia (5)14%—Microsoft Internet Information Server24/1/199916/6/2026
Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.
ModificadaAlta (10)24%—Microsoft Internet Information Server14/1/199916/6/2026
Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.
ModificadaBaja (2.1)25%💥 ExploitMicrosoft Internet Information Server14/1/199916/6/2026
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.
ModificadaMedia (5)25%💥 ExploitMicrosoft Internet Information Server1/1/199916/6/2026
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
ModificadaMedia (5)7.6%—C2net Stonghold WEB ServerHP Open Market Secure WebserverMicrosoft Exchange ServerMicrosoft Internet Information Server+926/6/199816/6/2026
Information from SSL-encrypted sessions via PKCS #1.