Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3142▲ 566 respecto a la semana anterior
Críticas / altas1456▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
–

1918 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)62%—Microsoft Internet Information ServerMicrosoft Internet Information Services22/4/200216/6/2026
Desbordamiento de buffer en el mecanismo de transferencia de datos de Internet Information Server (IIS) 4.0, 5.0 y 5.1 permite a atacantes remotos causar una denegación de servicio o ejecutar código, tambien conocido como "Variante del desbordamiento de buffer en codificación troceada"
ModificadaMedia (5)57%—Microsoft Internet Information ServerMicrosoft Internet Information Services22/4/200216/6/2026
Un filtro ISAPI en las Extensiones de Servidor de Front Page y ASP.NET para Internet Information Server (IIS) 4.0, 5.0 y 5.1 no maneja adecuadamente la condición de error cuando se provee una URL larga, lo que permite a atacantes remotos causar una denegación de sevicio (caída).
ModificadaMedia (5)35%💥 ExploitMicrosoft Internet Information Services11/12/200116/6/2026
Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection.
ModificadaAlta (7.2)0.97%💥 ExploitSGI Performance Co-pilot6/12/200116/6/2026
The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCP_LOG_DIR).
ModificadaAlta (7.5)19%—Microsoft Internet Information Services20/11/200116/6/2026
Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters.
ModificadaBaja (2.1)2.4%—Microsoft Internet Information Services30/10/200116/6/2026
IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type table.
ModificadaMedia (5)18%—Microsoft Internet Information Server30/10/200116/6/2026
IIS 4.0 with URL redirection enabled allows remote attackers to cause a denial of service (crash) via a malformed request that specifies a length that is different than the actual length.
ModificadaAlta (7.5)1.6%—Emergenices Personnel Information System Empris2/10/200116/6/2026
Empris PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
ModificadaMedia (5)36%—Microsoft Internet Information Server20/9/200116/6/2026
Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode.
ModificadaAlta (7.2)8.8%💥 ExploitMicrosoft Internet Information Services20/9/200116/6/2026
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.
ModificadaMedia (5)27%—Microsoft Internet Information Services20/9/200116/6/2026
Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.
ModificadaAlta (7.2)69%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services20/9/200116/6/2026
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.
ModificadaMedia (5)7.1%💥 ExploitFaust Informatics Freestyle Chat14/8/200116/6/2026
Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (e.g., GET /aux HTTP/1.0).
ModificadaMedia (5)3.7%💥 ExploitFaust Informatics Freestyle Chat14/8/200116/6/2026
Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'.
ModificadaAlta (10)97%💥 ExploitMicrosoft Index ServerMicrosoft Indexing ServiceMicrosoft Internet Information Server21/7/200116/6/2026
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code…
ModificadaMedia (5)71%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services4/7/200116/6/2026
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that…
ModificadaAlta (7.5)91%💥 ExploitMicrosoft Internet Information Server27/6/200116/6/2026
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.
ModificadaMedia (5)21%—Microsoft Internet Information Server27/6/200116/6/2026
FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters.
ModificadaMedia (5)5.0%—Microsoft Internet Information Server27/6/200116/6/2026
The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.
ModificadaAlta (7.5)15%—Microsoft Internet Information Server27/6/200116/6/2026
FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.
ModificadaMedia (5)16%💥 ExploitMicrosoft Internet Information Server27/6/200116/6/2026
The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.
ModificadaMedia (5)68%💥 ExploitMicrosoft Internet Information Services2/6/200116/6/2026
IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.
ModificadaMedia (5)37%—Microsoft Exchange ServerMicrosoft Internet Information Services2/6/200116/6/2026
IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
ModificadaMedia (5)28%—Microsoft Internet Information ServerMicrosoft Internet Information Services12/2/200116/6/2026
IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.
ModificadaMedia (5)17%—Microsoft Internet Information Server12/2/200116/6/2026
Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.
Orbitaley — Vulnerabilidades