Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3142▲ 572 respecto a la semana anterior
Críticas / altas1455▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
–

1918 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)10%—Microsoft Internet Information Server21/1/200016/6/2026
IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page.
ModificadaMedia (5)28%—Microsoft Internet Information ServerMicrosoft Internet Information Services11/1/200016/6/2026
IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.
ModificadaAlta (7.5)11%—Microsoft Internet Information ServerMicrosoft Visual Interdev31/12/199916/6/2026
Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0.
ModificadaMedia (5)23%—Microsoft Internet Information Server31/12/199916/6/2026
IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.
ModificadaMedia (5)17%—Microsoft Internet Information Server31/12/199916/6/2026
IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.
ModificadaMedia (5)40%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services31/12/199916/6/2026
IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.
ModificadaMedia (5)17%—Microsoft Internet Information Server31/12/199916/6/2026
FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.
ModificadaMedia (5)18%—Microsoft Internet Information ServerMicrosoft Site Server31/12/199916/6/2026
The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.
ModificadaAlta (7.5)5.5%—Microsoft Internet Information Server31/12/199916/6/2026
IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.
ModificadaMedia (5)35%—Microsoft Internet Information ServerMicrosoft Site ServerMicrosoft Site Server Commerce21/12/199916/6/2026
IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.
ModificadaMedia (6.4)12%—Microsoft Internet Information ServerMicrosoft Site ServerMicrosoft Site Server Commerce21/12/199916/6/2026
IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.
ModificadaAlta (7.5)12%—Microsoft Commercial Internet SystemMicrosoft Internet Information Server23/9/199916/6/2026
IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.
ModificadaAlta (7.1)25%💥 ExploitMicrosoft Internet Information Server19/8/199916/6/2026
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".
ModificadaMedia (5)22%💥 ExploitMicrosoft Commercial Internet SystemMicrosoft Internet Information ServerMicrosoft Site Server11/8/199916/6/2026
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
ModificadaBaja (2.6)3.2%—Microsoft Commercial Internet SystemMicrosoft Internet Information ServerMicrosoft Site ServerMicrosoft Site Server Commerce11/8/199916/6/2026
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
ModificadaAlta (10)77%💥 ExploitMicrosoft Data Access ComponentsMicrosoft Index ServerMicrosoft Internet Information ServerMicrosoft Site Server19/7/199916/6/2026
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
ModificadaMedia (5)8.5%—Microsoft Internet Information Server7/7/199916/6/2026
IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.
ModificadaMedia (5)18%—Microsoft Internet Information Server6/7/199916/6/2026
The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.
ModificadaAlta (10)75%💥 ExploitMicrosoft Internet Information ServerMicrosoft Windows 2000Microsoft Windows NT16/6/199916/6/2026
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
ModificadaMedia (5)5.9%—Microsoft Internet Information Server12/5/199916/6/2026
Denial of service in Windows NT IIS server using ..\..
ModificadaMedia (5)28%—Microsoft Internet Information Server7/5/199916/6/2026
The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
ModificadaMedia (5)29%—Microsoft Internet Information Server7/5/199916/6/2026
The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
ModificadaMedia (5)45%💥 ExploitMicrosoft Internet Information Server7/5/199916/6/2026
The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
ModificadaMedia (5)29%—Microsoft Internet Information Server7/5/199916/6/2026
The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
ModificadaAlta (7.5)10%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services19/2/199916/6/2026
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.