Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Microsoft-IIS Number Of NVD 104 CRITICAL 0 HIGH 40 MEDIUM 59 LOW 5
URL https://www.iis.net/
Explanation This is a web application server that comes with Windows.

IIS 7.5: Included with Windows 7 and Windows Server 2008 R2
IIS 8.0: Included with Windows 8 and Windows Server 2012
IIS 8.5: Included with Windows 8.1 and Windows Server 2012 R2
IIS 10.0: Included with Windows 10 and Windows Server 2016 and Windows Server 2019

The support expiration date will be determined according to the OS that is included.
Tag
  • Microsoft

Add Information URL
No Type Name URL

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
21 IIS 10.0 10.0 Oct. 12, 2016 Jan. 11, 2022 Jan. 11, 2027 0 0 0 0
22 IIS 8.5 8.5 Nov. 13, 2013 0 0 0 0
23 IIS 8.0 8.0 Oct. 30, 2012 0 0 0 0
24 IIS 7.5 7.5 Oct. 22, 2009 0 0 0 0
25 IIS 7.0 7.0 Jan. 25, 2007 0 0 0 0
26 IIS 6.0 6.0 May 28, 2003 0 6 4 1
27 IIS 5.1 5.1 Dec. 31, 2001 0 2 0 0
28 IIS 5.0 5.0 May 17, 2000 June 30, 2005 July 13, 2010 0 4 5 0
29 IIS 4.0 4.0 0 34 51 4
30 IIS 3.0 3.0 0 9 21 1
31 IIS 2.0 2.0 0 3 6 0
32 IIS 1.0 1.0 0 3 6 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
21 -
7.5
HIGH Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked E… NVD-CWE-Other
CVE-2002-0364 cpe:2.3:a:microsoft:internet_information_server:4.0:* 2018-10-31 01:25
2002-07-3
Show GitHub Exploit DB Packet Storm
22 -
7.5
HIGH Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code v… NVD-CWE-Other
CVE-2002-0071 cpe:2.3:a:microsoft:internet_information_server:4.0:* 2018-10-31 01:25
2002-04-22
Show GitHub Exploit DB Packet Storm
23 -
5.0
MEDIUM The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided… NVD-CWE-Other
CVE-2002-0072 cpe:2.3:a:microsoft:internet_information_server:4.0:* 2020-11-24 04:49
2002-04-22
Show GitHub Exploit DB Packet Storm
24 -
5.0
MEDIUM The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containi… NVD-CWE-Other
CVE-2002-0073 cpe:2.3:a:microsoft:internet_information_server:4.0:* 2020-11-24 04:49
2002-04-22
Show GitHub Exploit DB Packet Storm
25 -
7.5
HIGH Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session. NVD-CWE-Other
CVE-2002-0074 cpe:2.3:a:microsoft:internet_information_server:4.0:* 2020-11-24 04:49
2002-04-22
Show GitHub Exploit DB Packet Storm
26 -
7.5
HIGH Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL re… NVD-CWE-Other
CVE-2002-0075 cpe:2.3:a:microsoft:internet_information_server:4.0:* 2020-11-24 04:49
2002-04-22
Show GitHub Exploit DB Packet Storm
27 -
7.5
HIGH Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code. NVD-CWE-Other
CVE-2002-0079 cpe:2.3:a:microsoft:internet_information_server:4.0:* 2018-10-31 01:25
2002-04-22
Show GitHub Exploit DB Packet Storm
28 -
7.5
HIGH Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discover… NVD-CWE-Other
CVE-2002-0147 cpe:2.3:a:microsoft:internet_information_server:4.0:* 2020-11-24 04:49
2002-04-22
Show GitHub Exploit DB Packet Storm
29 -
7.5
HIGH Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page. NVD-CWE-Other
CVE-2002-0148 cpe:2.3:a:microsoft:internet_information_server:4.0:* 2020-11-24 04:49
2002-04-22
Show GitHub Exploit DB Packet Storm
30 -
7.5
HIGH Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names. NVD-CWE-Other
CVE-2002-0149 cpe:2.3:a:microsoft:internet_information_server:4.0:* 2020-11-24 04:49
2002-04-22
Show GitHub Exploit DB Packet Storm