Microsoft Exchange Server vulnerabilities
207 known vulnerabilities affecting microsoft/exchange_server.
Total CVEs
207
CISA KEV
19
actively exploited
Public exploits
28
Exploited in wild
19
Severity breakdown
CRITICAL24HIGH84MEDIUM93LOW6
Vulnerabilities
Page 8 of 11
CVE-2015-1630MEDIUMCVSS 4.3v20132015-03-11
CVE-2015-1630 [MEDIUM] CWE-79 CVE-2015-1630: Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013
Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Audit Report Cross Site Scripting Vulnerability."
nvd
CVE-2015-1631MEDIUMCVSS 5.0v20132015-03-11
CVE-2015-1631 [MEDIUM] CWE-284 CVE-2015-1631: Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to spoof meeting
Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to spoof meeting organizers via unspecified vectors, aka "Exchange Forged Meeting Request Spoofing Vulnerability."
nvd
CVE-2015-1629MEDIUMCVSS 4.3v20132015-03-11
CVE-2015-1629 [MEDIUM] CWE-79 CVE-2015-1629: Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013
Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "ExchangeDLP Cross Site Scripting Vulnerability."
nvd
CVE-2014-6325MEDIUMCVSS 4.3v20132014-12-11
CVE-2014-6325 [MEDIUM] CWE-79 CVE-2014-6325: Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability," a different vulnerability than CVE-2014-6326.
nvd
CVE-2014-6319MEDIUMCVSS 5.0v2007v2010+1 more2014-12-11
CVE-2014-6319 [MEDIUM] CWE-284 CVE-2014-6319: Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative U
Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requests, which allows remote attackers to spoof the origin of e-mail messages via unspecified vectors, aka "Outlook Web App Token Spoofing Vulnerability."
nvd
CVE-2014-6326MEDIUMCVSS 4.3v20132014-12-11
CVE-2014-6326 [MEDIUM] CVE-2014-6326: Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability," a different vulnerability than CVE-2014-6325.
nvd
CVE-2014-6336LOWCVSS 3.5v20132014-12-11
CVE-2014-6336 [LOW] CWE-20 CVE-2014-6336: Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properl
Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens, which allows remote attackers to redirect users to arbitrary web sites and spoof the origin of e-mail messages via unspecified vectors, aka "Exchange URL Redirection Vulnerability."
nvd
CVE-2013-5072MEDIUMCVSS 4.3v2010v20132013-12-11
CVE-2013-5072 [MEDIUM] CWE-79 CVE-2013-5072: Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2
Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."
nvd
CVE-2013-0418MEDIUMCVSS 6.8v2007v20102013-01-17
CVE-2013-0418 [MEDIUM] CVE-2013-0418: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-0393. NOTE: the previous information was obtained from the January 2013 CPU. Oracle has not comment
nvd
CVE-2012-4791LOWCVSS 3.5v2007v20102012-12-12
CVE-2012-4791 [LOW] CWE-94 CVE-2012-4791: Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a
Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."
nvd
CVE-2010-3937MEDIUMCVSS 4.0v20072010-12-16
CVE-2010-3937 [MEDIUM] CWE-399 CVE-2010-3937: Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a
Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability."
nvd
CVE-2010-2091MEDIUMCVSS 4.3PoCv20072010-05-27
CVE-2010-2091 [MEDIUM] CWE-79 CVE-2010-2091: Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is use
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
nvd
CVE-2010-1690MEDIUMCVSS 6.4v2003v2007+1 more2010-05-07
CVE-2010-1690 [MEDIUM] CVE-2010-1690: The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction
nvd
CVE-2010-1689MEDIUMCVSS 6.4v2003v2007+1 more2010-05-07
CVE-2010-1689 [MEDIUM] CVE-2010-1689: The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs
nvd
CVE-2010-0024MEDIUMCVSS 5.0v2000v2003+2 more2010-04-14
CVE-2010-0024 [MEDIUM] CWE-20 CVE-2010-0024: The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 G
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."
nvd
CVE-2010-0025MEDIUMCVSS 5.0v2000v2003+2 more2010-04-14
CVE-2010-0025 [MEDIUM] CWE-200 CVE-2010-0025: The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 G
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and then sending a STARTTLS command, a
nvd
CVE-2009-0098CRITICALCVSS 9.3v2000v2003+1 more2009-02-10
CVE-2009-0098 [CRITICAL] CWE-399 CVE-2009-0098: Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not pr
Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."
nvd
CVE-2009-0099MEDIUMCVSS 5.0v2000v2003+1 more2009-02-10
CVE-2009-0099 [MEDIUM] CWE-20 CVE-2009-0099: The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 S
The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability."
nvd
CVE-2008-1547MEDIUMCVSS 4.3PoCv20032008-10-21
CVE-2008-1547 [MEDIUM] CWE-601 CVE-2008-1547: Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Excha
Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.
nvd
CVE-2008-2248MEDIUMCVSS 4.3v2003v20072008-07-08
CVE-2008-2248 [MEDIUM] CVE-2008-2248: Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 al
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified HTML, a different vulnerability than CVE-2008-2247.
nvd