Microsoft Lync vulnerabilities
5 known vulnerabilities affecting microsoft/microsoft_lync.
Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2019-1084MEDIUMCVSS 6.5v2013 Service Pack 1 (32-bit)v2013 Service Pack 1 (64-bit)2019-07-15
CVE-2019-1084 [MEDIUM] CWE-200 CVE-2019-1084: An information disclosure vulnerability exists when Exchange allows creation of entities with Displa
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by valida
cvelistv5nvd
CVE-2018-8546MEDIUMCVSS 5.9v2013 Service Pack 1 (32-bit)v2013 Service Pack 1 (64-bit)+2 more2018-11-14
CVE-2018-8546 [MEDIUM] CVE-2018-8546: A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business De
A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype.
cvelistv5nvd
CVE-2018-8474HIGHCVSS 7.5PoCvMac 20112018-09-13
CVE-2018-8474 [HIGH] CWE-20 CVE-2018-8474: A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize spe
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Security Feature Bypass Vulnerability." This affects Microsoft Lync.
cvelistv5nvd
CVE-2018-8238HIGHCVSS 7.8v2013 Service Pack 1 (32-bit)v2013 Service Pack 1 (64-bit)2018-07-11
CVE-2018-8238 [HIGH] CVE-2018-8238: A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse
A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse UNC path links shared via messages, aka "Skype for Business and Lync Security Feature Bypass Vulnerability." This affects Skype, Microsoft Lync.
cvelistv5nvd
CVE-2018-8311HIGHCVSS 8.8v2013 Service Pack 1 (32-bit)v2013 Service Pack 1 (64-bit)2018-07-11
CVE-2018-8311 [HIGH] CWE-20 CVE-2018-8311: A remote code execution vulnerability exists when Skype for Business and Microsoft Lync clients fail
A remote code execution vulnerability exists when Skype for Business and Microsoft Lync clients fail to properly sanitize specially crafted content, aka "Remote Code Execution Vulnerability in Skype For Business and Lync." This affects Skype, Microsoft Lync.
cvelistv5nvd