Commercial Internet System
6 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Commercial Internet System, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Commercial Internet System CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 6 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High2
- Medium3
- Low1
Latest CVEs
The 6 most recently published vulnerabilities affecting Commercial Internet System.
- CVE-2000-0246IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, a...5.0
- CVE-2000-0053Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.7.5
- CVE-1999-0910Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.5.0
- CVE-1999-0861Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.2.6
- CVE-1999-0777IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.7.5
- CVE-1999-0867Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.5.0
Product grouping is registry-driven, with AI assist and human review. How it works