Microsoft Exchange Server vulnerabilities

207 known vulnerabilities affecting microsoft/exchange_server.

Total CVEs
207
CISA KEV
19
actively exploited
Public exploits
28
Exploited in wild
19
Severity breakdown
CRITICAL24HIGH84MEDIUM93LOW6

Vulnerabilities

Page 11 of 11
CVE-2000-0524MEDIUMCVSS 5.0v4.0v5.02000-06-05
CVE-2000-0524 [MEDIUM] CVE-2000-0524: Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.
nvd
CVE-1999-1043MEDIUMCVSS 5.0v5.0v5.51999-12-31
CVE-1999-1043 [MEDIUM] CVE-1999-1043: Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malfo Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).
nvd
CVE-1999-0993HIGHCVSS 7.5v5.0v5.51999-12-13
CVE-1999-0993 [HIGH] CWE-665 CVE-1999-0993: Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.
nvd
CVE-1999-0682MEDIUMCVSS 5.0v5.51999-08-06
CVE-1999-0682 [MEDIUM] CVE-1999-0682: Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP a Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.
nvd
CVE-1999-0385CRITICALCVSS 10.0v5.51998-12-01
CVE-1999-0385 [CRITICAL] CWE-120 CVE-1999-0385: The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduc The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.
nvd
CVE-1999-0007MEDIUMCVSS 5.0v5.51998-06-26
CVE-1999-0007 [MEDIUM] CWE-327 CVE-1999-0007: Information from SSL-encrypted sessions via PKCS #1. Information from SSL-encrypted sessions via PKCS #1.
nvd
CVE-1999-0284HIGHCVSS 7.5PoCv4.0v5.01998-01-01
CVE-1999-0284 [HIGH] CWE-120 CVE-1999-0284: Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer over Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.
nvd