cbcvebase.

Microsoft Exchange Server vulnerabilities

219 known vulnerabilities affecting microsoft/exchange_server.

Total CVEs
219
CISA KEV
20
actively exploited
Public exploits
46
Exploited in wild
29
Severity breakdown
CRITICAL25HIGH89MEDIUM99LOW6

Vulnerabilities

Page 11 of 11
CVE-2001-0509P4MEDIUMCVSS 5.0v5.0v5.5+1 more2001-09-20
CVE-2001-0509 [MEDIUM] CWE-20 CVE-2001-0509: Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.
nvd
CVE-2001-0543P4MEDIUMCVSS 5.0v20002001-09-20
CVE-2001-0543 [MEDIUM] CWE-401 CVE-2001-0543: Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a de Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed posts.
nvd
CVE-2018-8604P4MEDIUMCVSS 4.3v2016-cumulative_update_10v2016-cumulative_update_112018-12-12
CVE-2018-8604 [MEDIUM] CVE-2018-8604: A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile dat A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server.
nvd
CVE-2014-6336P4LOWCVSS 3.5v20132014-12-11
CVE-2014-6336 [LOW] CWE-20 CVE-2014-6336: Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properl Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens, which allows remote attackers to redirect users to arbitrary web sites and spoof the origin of e-mail messages via unspecified vectors, aka "Exchange URL Redirection Vulnerability."
nvd
CVE-2020-17085P4MEDIUMCVSS 4.9v2013v2016+1 more2020-11-11
CVE-2020-17085 [MEDIUM] CVE-2020-17085: Microsoft Exchange Server Denial of Service Vulnerability Microsoft Exchange Server Denial of Service Vulnerability
nvd
CVE-2001-0340P4HIGHCVSS 7.5v5.5v20002001-07-21
CVE-2001-0340 [HIGH] CWE-434 CVE-2001-0340: An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and In An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
nvd
CVE-1999-1043P4MEDIUMCVSS 5.0v5.0v5.51999-12-31
CVE-1999-1043 [MEDIUM] CVE-1999-1043: Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malfo Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).
nvd
CVE-2005-0563P4MEDIUMCVSS 4.3v5.52005-06-14
CVE-2005-0563 [MEDIUM] CWE-79 CVE-2005-0563: Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL ("javAsc ript:") in an IMG tag.
nvd
CVE-2022-30134P4MEDIUMCVSS 4.3v2013v2016+1 more2022-08-09
CVE-2022-30134 [MEDIUM] CVE-2022-30134: Microsoft Exchange Server Information Disclosure Vulnerability Microsoft Exchange Server Information Disclosure Vulnerability
nvd
CVE-2000-1006P4MEDIUMCVSS 5.0v5.52000-12-11
CVE-2000-1006 [MEDIUM] CVE-2000-1006: Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability.
nvd
CVE-1999-0007P4MEDIUMCVSS 5.0v5.51998-06-26
CVE-1999-0007 [MEDIUM] CWE-327 CVE-1999-0007: Information from SSL-encrypted sessions via PKCS #1. Information from SSL-encrypted sessions via PKCS #1.
nvd
CVE-2005-0738P4MEDIUMCVSS 5.0v20032005-05-02
CVE-2005-0738 [MEDIUM] CWE-400 CVE-2005-0738: Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.
nvd
CVE-2002-1873P4MEDIUMCVSS 5.0v20002002-12-31
CVE-2002-1873 [MEDIUM] CWE-400 CVE-2002-1873: Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attac Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.
nvd
CVE-2012-4791P4LOWCVSS 3.5v2007v20102012-12-12
CVE-2012-4791 [LOW] CWE-94 CVE-2012-4791: Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."
nvd
CVE-2002-0368P4MEDIUMCVSS 5.0v20002002-06-18
CVE-2002-0368 [MEDIUM] CWE-400 CVE-2002-0368: The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (C The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."
nvd
CVE-2000-0524P4MEDIUMCVSS 5.0v4.0v5.02000-06-05
CVE-2000-0524 [MEDIUM] CVE-2000-0524: Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.
nvd
CVE-2002-1876P4LOWCVSS 2.1v20002002-12-31
CVE-2002-1876 [LOW] CWE-400 CVE-2002-1876: Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a lar Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.
nvd
CVE-2002-0507P4LOWCVSS 2.1v5.5v20002002-08-12
CVE-2002-0507 [LOW] CWE-287 CVE-2002-0507: An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to byp An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.
nvd
CVE-2001-0666P4LOWCVSS 2.1v20002001-10-30
CVE-2001-0666 [LOW] CWE-400 CVE-2001-0666: Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial o Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.
nvd
Microsoft Exchange Server vulnerabilities | cvebase