Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 572 respecto a la semana anterior
Críticas / altas1455▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
1918 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 10% | — | Microsoft Internet Information Server | 21/1/2000 | 16/6/2026 | IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page. | |
| Modificada | Media (5) | 28% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 11/1/2000 | 16/6/2026 | IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. | |
| Modificada | Alta (7.5) | 11% | — | Microsoft Internet Information ServerMicrosoft Visual Interdev | 31/12/1999 | 16/6/2026 | Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0. | |
| Modificada | Media (5) | 23% | — | Microsoft Internet Information Server | 31/12/1999 | 16/6/2026 | IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters. | |
| Modificada | Media (5) | 17% | — | Microsoft Internet Information Server | 31/12/1999 | 16/6/2026 | IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability. | |
| Modificada | Media (5) | 40% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 31/12/1999 | 16/6/2026 | IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL. | |
| Modificada | Media (5) | 17% | — | Microsoft Internet Information Server | 31/12/1999 | 16/6/2026 | FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time. | |
| Modificada | Media (5) | 18% | — | Microsoft Internet Information ServerMicrosoft Site Server | 31/12/1999 | 16/6/2026 | The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files. | |
| Modificada | Alta (7.5) | 5.5% | — | Microsoft Internet Information Server | 31/12/1999 | 16/6/2026 | IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability. | |
| Modificada | Media (5) | 35% | — | Microsoft Internet Information ServerMicrosoft Site ServerMicrosoft Site Server Commerce | 21/12/1999 | 16/6/2026 | IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability. | |
| Modificada | Media (6.4) | 12% | — | Microsoft Internet Information ServerMicrosoft Site ServerMicrosoft Site Server Commerce | 21/12/1999 | 16/6/2026 | IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability. | |
| Modificada | Alta (7.5) | 12% | — | Microsoft Commercial Internet SystemMicrosoft Internet Information Server | 23/9/1999 | 16/6/2026 | IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions. | |
| Modificada | Alta (7.1) | 25% | 💥 Exploit | Microsoft Internet Information Server | 19/8/1999 | 16/6/2026 | When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". | |
| Modificada | Media (5) | 22% | 💥 Exploit | Microsoft Commercial Internet SystemMicrosoft Internet Information ServerMicrosoft Site Server | 11/8/1999 | 16/6/2026 | Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. | |
| Modificada | Baja (2.6) | 3.2% | — | Microsoft Commercial Internet SystemMicrosoft Internet Information ServerMicrosoft Site ServerMicrosoft Site Server Commerce | 11/8/1999 | 16/6/2026 | Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. | |
| Modificada | Alta (10) | 77% | 💥 Exploit | Microsoft Data Access ComponentsMicrosoft Index ServerMicrosoft Internet Information ServerMicrosoft Site Server | 19/7/1999 | 16/6/2026 | The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands. | |
| Modificada | Media (5) | 8.5% | — | Microsoft Internet Information Server | 7/7/1999 | 16/6/2026 | IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL. | |
| Modificada | Media (5) | 18% | — | Microsoft Internet Information Server | 6/7/1999 | 16/6/2026 | The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character. | |
| Modificada | Alta (10) | 75% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Windows 2000Microsoft Windows NT | 16/6/1999 | 16/6/2026 | Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions. | |
| Modificada | Media (5) | 5.9% | — | Microsoft Internet Information Server | 12/5/1999 | 16/6/2026 | Denial of service in Windows NT IIS server using ..\.. | |
| Modificada | Media (5) | 28% | — | Microsoft Internet Information Server | 7/5/1999 | 16/6/2026 | The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | |
| Modificada | Media (5) | 29% | — | Microsoft Internet Information Server | 7/5/1999 | 16/6/2026 | The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | |
| Modificada | Media (5) | 45% | 💥 Exploit | Microsoft Internet Information Server | 7/5/1999 | 16/6/2026 | The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | |
| Modificada | Media (5) | 29% | — | Microsoft Internet Information Server | 7/5/1999 | 16/6/2026 | The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 19/2/1999 | 16/6/2026 | In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. |