VendorsMicrosoftcommercial_internet_system2.5
Vulnerabilities

Microsoft commercial_internet_system 2.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2000-0053
Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.
Published 2000-04-18 · Modified
7.5EPSS 0.147
CVE-1999-0777
IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.
Published 2000-01-04 · Modified
7.5EPSS 0.120
CVE-2000-0246
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.
Published 2000-06-02 · Modified
5.01 PoCEPSS 0.800
CVE-1999-0867
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
Published 2000-01-04 · Modified
5.01 PoCEPSS 0.215
CVE-1999-0910
Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.
Published 2000-02-04 · Modified
5.0EPSS 0.058
CVE-1999-0861
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
Published 2000-01-04 · Modified
2.6EPSS 0.032