Show filters
30 Total Results
Displaying 11-20 of 30
Sort by:
Attacker Value
Unknown
CVE-1999-1451
Disclosure Date: December 31, 1999 (last updated February 22, 2025)
The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.
0
Attacker Value
Unknown
CVE-2000-0024
Disclosure Date: December 21, 1999 (last updated February 22, 2025)
IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.
0
Attacker Value
Unknown
CVE-2000-0025
Disclosure Date: December 21, 1999 (last updated February 22, 2025)
IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.
0
Attacker Value
Unknown
CVE-1999-0725
Disclosure Date: August 19, 1999 (last updated February 22, 2025)
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".
0
Attacker Value
Unknown
CVE-1999-0867
Disclosure Date: August 11, 1999 (last updated February 22, 2025)
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
0
Attacker Value
Unknown
CVE-1999-0861
Disclosure Date: August 11, 1999 (last updated February 22, 2025)
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
0
Attacker Value
Unknown
CVE-1999-1011
Disclosure Date: July 19, 1999 (last updated February 22, 2025)
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-1999-1537
Disclosure Date: July 07, 1999 (last updated February 22, 2025)
IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.
0
Attacker Value
Unknown
CVE-1999-1478
Disclosure Date: July 06, 1999 (last updated February 22, 2025)
The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.
0
Attacker Value
Unknown
CVE-1999-0412
Disclosure Date: February 19, 1999 (last updated February 22, 2025)
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
0