
CVE-1999-1537
https://notcve.org/view.php?id=CVE-1999-1537
07 Jul 1999 — IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL. • http://marc.info/?l=ntbugtraq&m=93138827329577&w=2 •

CVE-1999-1478
https://notcve.org/view.php?id=CVE-1999-1478
06 Jul 1999 — The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character. • http://marc.info/?l=ntbugtraq&m=93138827429589&w=2 •

CVE-1999-0874 – Microsoft IIS 4.0 - Remote Buffer Overflow
https://notcve.org/view.php?id=CVE-1999-0874
16 Jun 1999 — Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions. • https://www.exploit-db.com/exploits/19247 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-1999-0736 – Microsoft IIS 4.0 / Microsoft Site Server 3.0 - Showcode ASP
https://notcve.org/view.php?id=CVE-1999-0736
07 May 1999 — The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. • https://www.exploit-db.com/exploits/19129 •

CVE-1999-0737
https://notcve.org/view.php?id=CVE-1999-0737
07 May 1999 — The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. • https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-013 •

CVE-1999-0738
https://notcve.org/view.php?id=CVE-1999-0738
07 May 1999 — The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. • https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-013 •

CVE-1999-0739
https://notcve.org/view.php?id=CVE-1999-0739
07 May 1999 — The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. • https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-013 •

CVE-1999-0412 – Microsoft IIS 2.0/3.0/4.0 - ISAPI GetExtensionVersion()
https://notcve.org/view.php?id=CVE-1999-0412
19 Feb 1999 — In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. • https://www.exploit-db.com/exploits/19376 •

CVE-1999-1375 – Microsoft IIS 3.0/4.0 - Using ASP and FSO To Read Server Files
https://notcve.org/view.php?id=CVE-1999-1375
11 Feb 1999 — FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. • https://www.exploit-db.com/exploits/19194 •

CVE-1999-0407
https://notcve.org/view.php?id=CVE-1999-0407
09 Feb 1999 — By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. • http://marc.info/?l=bugtraq&m=91983486431506&w=2 •