CVE-1999-1537
Last modified
CVE-1999-1537 is a vulnerability of currently unknown severity. IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.. EPSS estimates a 8.53% chance of exploitation in the next 30 days.
Description
IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Internet Information Server | 3.0 |
| Microsoft | Internet Information Server | 4.0 |
References
- http://www.securityfocus.com/bid/521Patch, Vendor Advisory
- http://www.securityfocus.com/bid/521Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-1999-1537?
How severe is CVE-1999-1537?
How do I fix CVE-1999-1537?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 1999
- CVE-1999-1531Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J al…
- CVE-1999-1532Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remot…
- CVE-1999-1533Eicon Technology Diva LAN ISDN modem allows a remote attacke…
- CVE-1999-1534Buffer overflow in (1) nlservd and (2) rnavc in Knox Softwar…
- CVE-1999-1535Buffer overflow in AspUpload.dll in Persits Software AspUplo…
- CVE-1999-1536.sbstart startup script in AcuShop Salesbuilder is world wri…
- CVE-1999-1538When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertent…
- CVE-1999-1539Buffer overflow in FTP server in QPC Software's QVT/Term Plu…
- CVE-1999-1540shell-lock in Cactus Software Shell Lock uses weak encryptio…
- CVE-1999-1541shell-lock in Cactus Software Shell Lock allows local users …
- CVE-1999-1542RPMMail before 1.4 allows remote attackers to execute comman…
- CVE-1999-1543MacOS uses weak encryption for passwords that are stored in …
Are you affected by CVE-1999-1537?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
