Isa Server
Vendor:
First CVE: Jul 2, 2001 · Active for 25 years
21
Total CVEs
More Total CVEs than 94% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Isa Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 2, 2001
25 years ago
Most Recent CVE
Aug 12, 2009
6,189 days ago
CVE Severity & Scoring
Isa Server21 CVEs
33%
62%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (4.8%)
Unknown20 (95.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (4.8%)
High0 (0.0%)
Unknown20 (95.2%)
User Interaction
None1 (4.8%)
Unknown20 (95.2%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (4.8%)
Unknown20 (95.2%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1136HIGH The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 | Jul 15, 2009 | 9.3 | 79 | NO | YES |
CVE-2009-1534HIGH Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visu | Aug 12, 2009 | 9.3 | 70 | NO | YES |
CVE-2002-0371HIGH Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gophe | Jul 3, 2002 | 7.5 | 61 | NO | YES |
CVE-2003-0526MEDIUM Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containi | Aug 18, 2003 | 6.8 | 44 | NO | YES |
CVE-2001-0239HIGH Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type. | Jul 2, 2001 | 7.5 | 42 | NO | YES |
CVE-2009-1135HIGH Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to | Jul 15, 2009 | 9.0 | 36 | NO | NO |
CVE-2009-0562HIGH The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 | Aug 12, 2009 | 9.3 | 35 | NO | NO |
CVE-2004-0892HIGH Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to | Jan 27, 2005 | 7.5 | 32 | NO | NO |
CVE-2006-7027HIGH Microsoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remote attackers to manipulate port | Feb 23, 2007 | 10.0 | 31 | NO | NO |
CVE-2005-1216HIGH Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) pred | Jun 14, 2005 | 7.5 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
9.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
23.8% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Isa Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2006 | 4 | 9.2 | 42.0% | 0 | 2 |
| 2004 | 7 | 8.3 | 32.7% | 0 | 2 |
| 2000 | 13 | 6.2 | 21.5% | 0 | 3 |