Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3146▲ 578 respecto a la semana anterior
Críticas / altas1455▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
–

1918 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)31%💥 ExploitMicrosoft Internet Information Server11/2/199916/6/2026
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.
ModificadaAlta (10)5.1%—Microsoft Internet Information Server9/2/199916/6/2026
By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.
ModificadaMedia (5)11%—Microsoft Internet Information Server27/1/199916/6/2026
IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.
ModificadaAlta (7.5)18%—Microsoft Internet Information Server27/1/199916/6/2026
A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.
ModificadaAlta (7.8)49%—Microsoft Internet Information Server26/1/199916/6/2026
The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.
ModificadaAlta (7.5)19%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services26/1/199916/6/2026
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
ModificadaMedia (5)14%—Microsoft Internet Information Server24/1/199916/6/2026
Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.
ModificadaAlta (10)24%—Microsoft Internet Information Server14/1/199916/6/2026
Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.
ModificadaBaja (2.1)25%💥 ExploitMicrosoft Internet Information Server14/1/199916/6/2026
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.
ModificadaMedia (5)25%💥 ExploitMicrosoft Internet Information Server1/1/199916/6/2026
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
ModificadaAlta (10)7.6%—Microsoft Internet Information ServicesAI1/1/199916/6/2026
IIS has the #exec function enabled for Server Side Include (SSI) files.
ModificadaMedia (5)7.6%—C2net Stonghold WEB ServerHP Open Market Secure WebserverMicrosoft Exchange ServerMicrosoft Internet Information Server+926/6/199816/6/2026
Information from SSL-encrypted sessions via PKCS #1.
ModificadaMedia (5)65%💥 ExploitMicrosoft Internet Information ServerMicrosoft Windows NT1/6/199816/6/2026
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
ModificadaAlta (7)19%—Microsoft FrontpageMicrosoft Internet Information ServerMicrosoft Personal WEB ServerNetscape Enterprise Server+16/2/199816/6/2026
Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
ModificadaMedia (6.4)53%💥 ExploitMicrosoft Internet Information Server1/9/199716/6/2026
IIS newdsn.exe CGI script allows remote users to overwrite files.
ModificadaMedia (5)13%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services1/6/199716/6/2026
Denial of service in IIS using long URLs.
ModificadaAlta (7.5)8.0%—Microsoft Internet Information ServerMicrosoft Internet Information Services1/1/199716/6/2026
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.
ModificadaAlta (10)16%💥 ExploitMicrosoft Internet Information Services25/2/199616/6/2026
IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.