Internet Information Server

Vendor:

First CVE: Jan 1, 1997 · Active for 29 years

111
Total CVEs
More Total CVEs than 99% of tracked products
7.4
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Internet Information Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 1997
29 years ago
Most Recent CVE
May 22, 2013
4,811 days ago

CVE Severity & Scoring

Internet Information Server111 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (2.7%)
Unknown108 (97.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (1.8%)
High1 (0.9%)
Unknown108 (97.3%)
User Interaction
None3 (2.7%)
Unknown108 (97.3%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (2.7%)
Unknown108 (97.3%)

Top CVEs

Signals from CVEs in this product scope (111 CVEs).

111 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a l
Jul 21, 200110.090NOYES
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (
Aug 31, 20099.088NOYES
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.
Jun 27, 20017.586NOYES
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute a
Jul 19, 199910.083NOYES
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
Jun 16, 199910.081NOYES
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characte
Dec 19, 20007.573NOYES
Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pa
Jul 11, 20066.572NOYES
The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application cr
Nov 3, 20045.071NOYES
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm d
Jul 13, 20002.670NOYES
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or exe
Apr 22, 20027.567NOYES

Exploit Exposure

Signals from CVEs in this product scope (111 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
7 CVEs
6.3% of CVEs· 97th percentile
Nuclei
1 CVE
0.9% of CVEs· 96th percentile
ExploitDB
39 CVEs
35.1% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (111 CVEs).

Media Mentions

Signals from CVEs in this product scope (111 CVEs).

Top CNAs Publishing CVEs For Internet Information Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.096.746.1%03
5.015.016.7%00
4.0826.031.0%030
3.0235.828.7%012