peter bassill · operator
$ cve CVE-1999-0867 JSON

CVE-1999-0867 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 21.5% (pctl 98)

Patch early

A public exploit exists.

Description

Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS21.53% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published1999-08-11
Last modified2026-06-16

Affected (3)

VendorProduct
microsoftcommercial internet system
microsoftinternet information server
microsoftsite server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD