CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2017-7269CRITICAL | Microsoft Windows Server Buffer Overflow VulnerabilityBuffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016. | CVSS9.8v3.1 | EPSS99.8% | PoCs22 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
Microsoft Internet Information Services (IIS) Uncontrolled Resource ConsumptionStack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability." CWE-400Sep 4, 2009 | CVSS5.0v2.0 | EPSS82.3% | PoCs3 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX | |
Microsoft Internet Information Services (IIS) Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability." CWE-120Aug 31, 2009 | CVSS9.0v2.0 | EPSS90.9% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Microsoft Internet Information Services (IIS) Integer Overflow or WraparoundInteger overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability." CWE-190Oct 15, 2008 | CVSS9.0v2.0 | EPSS46.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Microsoft IIS SERVER_NAME Variable Bypass VulnerabilityMicrosoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost. Aug 23, 2005 | CVSS5.0v2.0 | EPSS39.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Microsoft Internet Information Services (IIS) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice. Sep 18, 2001 | CVSS7.5v2.0 | EPSS90.8% | PoCs10 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Microsoft IIS 4.0 and 5.0 Folder Traversal VulnerabilityIIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability. Jan 22, 2001 | CVSS7.5v2.0 | EPSS70.6% | PoCs9 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Microsoft Internet Information Services (IIS) Exposure of Sensitive Information to an Unauthorized ActorIIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. Feb 4, 2000 | CVSS5.0v2.0 | EPSS26.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |