Vulnerabilities > Microsoft > Internet Information Server > 4.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2002-04-22 | CVE-2002-0071 | Buffer Overflow vulnerability in Microsoft products Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names. | 7.5 |
2001-10-30 | CVE-2001-0545 | Unspecified vulnerability in Microsoft Internet Information Server 4.0 IIS 4.0 with URL redirection enabled allows remote attackers to cause a denial of service (crash) via a malformed request that specifies a length that is different than the actual length. | 5.0 |
2001-09-20 | CVE-2001-0709 | Unspecified vulnerability in Microsoft Internet Information Server Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode. | 5.0 |
2001-09-20 | CVE-2001-0506 | Buffer Overrun Privelege Elevation vulnerability in Microsoft products Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability. | 7.2 |
2001-07-04 | CVE-2001-1243 | Local DoS vulnerability in Microsoft products Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject. | 5.0 |
2001-06-27 | CVE-2001-0337 | Denial-Of-Service vulnerability in IIS Far East Edition The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests. | 5.0 |
2001-06-27 | CVE-2001-0336 | Denial-Of-Service vulnerability in IIS Far East Edition The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request. | 5.0 |
2001-06-27 | CVE-2001-0335 | Unspecified vulnerability in Microsoft Internet Information Server FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters. | 5.0 |
2001-06-27 | CVE-2001-0334 | Incorrect Calculation of Buffer Size vulnerability in Microsoft Internet Information Server FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded. | 7.5 |
2001-06-27 | CVE-2001-0333 | Unspecified vulnerability in Microsoft Internet Information Server Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. | 7.5 |