Page 15 of 107 results (0.004 seconds)

CVSS: 5.0EPSS: 1%CPEs: 1EXPL: 0

FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time. • http://support.microsoft.com/support/kb/articles/Q189/2/62.ASP https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-006 https://exchange.xforce.ibmcloud.com/vulnerabilities/1215 •

CVSS: 5.0EPSS: 2%CPEs: 1EXPL: 0

IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters. • http://support.microsoft.com/support/kb/articles/q187/5/03.asp https://exchange.xforce.ibmcloud.com/vulnerabilities/3892 •

CVSS: 7.5EPSS: 2%CPEs: 2EXPL: 0

Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0. • http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00276.html http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00277.html http://www.securityfocus.com/bid/190 •

CVSS: 5.0EPSS: 90%CPEs: 2EXPL: 1

IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL. • https://www.exploit-db.com/exploits/20481 https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0154 •

CVSS: 5.0EPSS: 1%CPEs: 2EXPL: 0

IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability. • http://support.microsoft.com/support/kb/articles/q192/2/96.asp https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-019 https://exchange.xforce.ibmcloud.com/vulnerabilities/1823 •