Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 566 respecto a la semana anterior
Críticas / altas1456▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
1918 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 62% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 22/4/2002 | 16/6/2026 | Desbordamiento de buffer en el mecanismo de transferencia de datos de Internet Information Server (IIS) 4.0, 5.0 y 5.1 permite a atacantes remotos causar una denegación de servicio o ejecutar código, tambien conocido como "Variante del desbordamiento de buffer en codificación troceada" | |
| Modificada | Media (5) | 57% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 22/4/2002 | 16/6/2026 | Un filtro ISAPI en las Extensiones de Servidor de Front Page y ASP.NET para Internet Information Server (IIS) 4.0, 5.0 y 5.1 no maneja adecuadamente la condición de error cuando se provee una URL larga, lo que permite a atacantes remotos causar una denegación de sevicio (caída). | |
| Modificada | Media (5) | 35% | 💥 Exploit | Microsoft Internet Information Services | 11/12/2001 | 16/6/2026 | Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection. | |
| Modificada | Alta (7.2) | 0.97% | 💥 Exploit | SGI Performance Co-pilot | 6/12/2001 | 16/6/2026 | The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCP_LOG_DIR). | |
| Modificada | Alta (7.5) | 19% | — | Microsoft Internet Information Services | 20/11/2001 | 16/6/2026 | Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters. | |
| Modificada | Baja (2.1) | 2.4% | — | Microsoft Internet Information Services | 30/10/2001 | 16/6/2026 | IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type table. | |
| Modificada | Media (5) | 18% | — | Microsoft Internet Information Server | 30/10/2001 | 16/6/2026 | IIS 4.0 with URL redirection enabled allows remote attackers to cause a denial of service (crash) via a malformed request that specifies a length that is different than the actual length. | |
| Modificada | Alta (7.5) | 1.6% | — | Emergenices Personnel Information System Empris | 2/10/2001 | 16/6/2026 | Empris PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | |
| Modificada | Media (5) | 36% | — | Microsoft Internet Information Server | 20/9/2001 | 16/6/2026 | Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode. | |
| Modificada | Alta (7.2) | 8.8% | 💥 Exploit | Microsoft Internet Information Services | 20/9/2001 | 16/6/2026 | IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability. | |
| Modificada | Media (5) | 27% | — | Microsoft Internet Information Services | 20/9/2001 | 16/6/2026 | Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request. | |
| Modificada | Alta (7.2) | 69% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 20/9/2001 | 16/6/2026 | Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Faust Informatics Freestyle Chat | 14/8/2001 | 16/6/2026 | Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (e.g., GET /aux HTTP/1.0). | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Faust Informatics Freestyle Chat | 14/8/2001 | 16/6/2026 | Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'. | |
| Modificada | Alta (10) | 97% | 💥 Exploit | Microsoft Index ServerMicrosoft Indexing ServiceMicrosoft Internet Information Server | 21/7/2001 | 16/6/2026 | Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code… | |
| Modificada | Media (5) | 71% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 4/7/2001 | 16/6/2026 | Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that… | |
| Modificada | Alta (7.5) | 91% | 💥 Exploit | Microsoft Internet Information Server | 27/6/2001 | 16/6/2026 | Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice. | |
| Modificada | Media (5) | 21% | — | Microsoft Internet Information Server | 27/6/2001 | 16/6/2026 | FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters. | |
| Modificada | Media (5) | 5.0% | — | Microsoft Internet Information Server | 27/6/2001 | 16/6/2026 | The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests. | |
| Modificada | Alta (7.5) | 15% | — | Microsoft Internet Information Server | 27/6/2001 | 16/6/2026 | FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded. | |
| Modificada | Media (5) | 16% | 💥 Exploit | Microsoft Internet Information Server | 27/6/2001 | 16/6/2026 | The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request. | |
| Modificada | Media (5) | 68% | 💥 Exploit | Microsoft Internet Information Services | 2/6/2001 | 16/6/2026 | IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests. | |
| Modificada | Media (5) | 37% | — | Microsoft Exchange ServerMicrosoft Internet Information Services | 2/6/2001 | 16/6/2026 | IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's. | |
| Modificada | Media (5) | 28% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 12/2/2001 | 16/6/2026 | IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability. | |
| Modificada | Media (5) | 17% | — | Microsoft Internet Information Server | 12/2/2001 | 16/6/2026 | Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character. |