Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 12% | — | Microsoft Internet Information ServerMicrosoft Site ServerMicrosoft Site Server Commerce | 21/12/1999 | 16/6/2026 | IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability. | |
| Modificada | Media (5) | 35% | — | Microsoft Internet Information ServerMicrosoft Site ServerMicrosoft Site Server Commerce | 21/12/1999 | 16/6/2026 | IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability. | |
| Modificada | Alta (7.5) | 12% | — | Microsoft Commercial Internet SystemMicrosoft Internet Information Server | 23/9/1999 | 16/6/2026 | IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions. | |
| Modificada | Alta (7.1) | 25% | 💥 Exploit | Microsoft Internet Information Server | 19/8/1999 | 16/6/2026 | When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". | |
| Modificada | Baja (2.6) | 3.2% | — | Microsoft Commercial Internet SystemMicrosoft Internet Information ServerMicrosoft Site ServerMicrosoft Site Server Commerce | 11/8/1999 | 16/6/2026 | Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. | |
| Modificada | Media (5) | 22% | 💥 Exploit | Microsoft Commercial Internet SystemMicrosoft Internet Information ServerMicrosoft Site Server | 11/8/1999 | 16/6/2026 | Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. | |
| Modificada | Alta (10) | 77% | 💥 Exploit | Microsoft Data Access ComponentsMicrosoft Index ServerMicrosoft Internet Information ServerMicrosoft Site Server | 19/7/1999 | 16/6/2026 | The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands. | |
| Modificada | Media (5) | 8.5% | — | Microsoft Internet Information Server | 7/7/1999 | 16/6/2026 | IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL. | |
| Modificada | Media (5) | 18% | — | Microsoft Internet Information Server | 6/7/1999 | 16/6/2026 | The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character. | |
| Modificada | Alta (10) | 75% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Windows 2000Microsoft Windows NT | 16/6/1999 | 16/6/2026 | Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions. | |
| Modificada | Media (5) | 5.9% | — | Microsoft Internet Information Server | 12/5/1999 | 16/6/2026 | Denial of service in Windows NT IIS server using ..\.. | |
| Modificada | Media (5) | 45% | 💥 Exploit | Microsoft Internet Information Server | 7/5/1999 | 16/6/2026 | The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | |
| Modificada | Media (5) | 28% | — | Microsoft Internet Information Server | 7/5/1999 | 16/6/2026 | The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | |
| Modificada | Media (5) | 29% | — | Microsoft Internet Information Server | 7/5/1999 | 16/6/2026 | The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | |
| Modificada | Media (5) | 29% | — | Microsoft Internet Information Server | 7/5/1999 | 16/6/2026 | The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 19/2/1999 | 16/6/2026 | In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. | |
| Modificada | Media (5) | 31% | 💥 Exploit | Microsoft Internet Information Server | 11/2/1999 | 16/6/2026 | FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. | |
| Modificada | Alta (10) | 5.1% | — | Microsoft Internet Information Server | 9/2/1999 | 16/6/2026 | By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. | |
| Modificada | Media (5) | 11% | — | Microsoft Internet Information Server | 27/1/1999 | 16/6/2026 | IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory. | |
| Modificada | Alta (7.5) | 18% | — | Microsoft Internet Information Server | 27/1/1999 | 16/6/2026 | A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 26/1/1999 | 16/6/2026 | In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). | |
| Modificada | Alta (7.8) | 49% | — | Microsoft Internet Information Server | 26/1/1999 | 16/6/2026 | The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts. | |
| Modificada | Media (5) | 14% | — | Microsoft Internet Information Server | 24/1/1999 | 16/6/2026 | Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command. | |
| Modificada | Baja (2.1) | 25% | 💥 Exploit | Microsoft Internet Information Server | 14/1/1999 | 16/6/2026 | When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password. | |
| Modificada | Alta (10) | 24% | — | Microsoft Internet Information Server | 14/1/1999 | 16/6/2026 | Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands. |