Page 8 of 91 results (0.007 seconds)

CVSS: 7.5EPSS: 1%CPEs: 2EXPL: 0

07 Jul 1999 — IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL. • http://marc.info/?l=ntbugtraq&m=93138827329577&w=2 •

CVSS: 7.5EPSS: 20%CPEs: 2EXPL: 0

06 Jul 1999 — The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character. • http://marc.info/?l=ntbugtraq&m=93138827429589&w=2 •

CVSS: 10.0EPSS: 85%CPEs: 4EXPL: 5

16 Jun 1999 — Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions. • https://www.exploit-db.com/exploits/19247 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.5EPSS: 76%CPEs: 1EXPL: 1

07 May 1999 — The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. • https://www.exploit-db.com/exploits/19129 •

CVSS: 7.5EPSS: 52%CPEs: 1EXPL: 0

07 May 1999 — The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. • https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-013 •

CVSS: 7.5EPSS: 46%CPEs: 1EXPL: 0

07 May 1999 — The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. • https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-013 •

CVSS: 7.5EPSS: 46%CPEs: 1EXPL: 0

07 May 1999 — The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. • https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-013 •

CVSS: 9.8EPSS: 38%CPEs: 3EXPL: 1

19 Feb 1999 — In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. • https://www.exploit-db.com/exploits/19376 •

CVSS: 7.5EPSS: 73%CPEs: 2EXPL: 2

11 Feb 1999 — FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. • https://www.exploit-db.com/exploits/19194 •

CVSS: 10.0EPSS: 29%CPEs: 1EXPL: 0

09 Feb 1999 — By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. • http://marc.info/?l=bugtraq&m=91983486431506&w=2 •