CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability. | 5 |
|||
Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request. | 7.5 |
|||
Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user. | 5 |
|||
IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions. | 7.5 |
|||
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. | 2.6 |
|||
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. | 5 |