Internet Information Server
Vendor:
First CVE: Jan 1, 1997 · Active for 29 years
111
Total CVEs
More Total CVEs than 99% of tracked products
7.4
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Internet Information Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 1997
29 years ago
Most Recent CVE
May 22, 2013
4,811 days ago
CVE Severity & Scoring
Internet Information Server111 CVEs
57%
38%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (2.7%)
Unknown108 (97.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (1.8%)
High1 (0.9%)
Unknown108 (97.3%)
User Interaction
None3 (2.7%)
Unknown108 (97.3%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (2.7%)
Unknown108 (97.3%)
Top CVEs
Signals from CVEs in this product scope (111 CVEs).
111 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0500HIGH Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a l | Jul 21, 2001 | 10.0 | 90 | NO | YES |
CVE-2009-3023HIGH Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST ( | Aug 31, 2009 | 9.0 | 88 | NO | YES |
CVE-2001-0333HIGH Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice. | Jun 27, 2001 | 7.5 | 86 | NO | YES |
CVE-1999-1011HIGH The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute a | Jul 19, 1999 | 10.0 | 83 | NO | YES |
CVE-1999-0874HIGH Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions. | Jun 16, 1999 | 10.0 | 81 | NO | YES |
CVE-2000-0884HIGH IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characte | Dec 19, 2000 | 7.5 | 73 | NO | YES |
CVE-2006-0026MEDIUM Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pa | Jul 11, 2006 | 6.5 | 72 | NO | YES |
CVE-2003-0718MEDIUM The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application cr | Nov 3, 2004 | 5.0 | 71 | NO | YES |
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm d | Jul 13, 2000 | 2.6 | 70 | NO | YES |
CVE-2002-0079HIGH Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or exe | Apr 22, 2002 | 7.5 | 67 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (111 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
7 CVEs
6.3% of CVEs· 97th percentile
Nuclei
1 CVE
0.9% of CVEs· 96th percentile
ExploitDB
39 CVEs
35.1% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (111 CVEs).
Media Mentions
Signals from CVEs in this product scope (111 CVEs).
Top CNAs Publishing CVEs For Internet Information Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.0 | 9 | 6.7 | 46.1% | 0 | 3 |
| 5.0 | 1 | 5.0 | 16.7% | 0 | 0 |
| 4.0 | 82 | 6.0 | 31.0% | 0 | 30 |
| 3.0 | 23 | 5.8 | 28.7% | 0 | 12 |