threat
engine
.sh
Back
·
··:··
Home
/
Product
/
microsoft exchange server
Product
microsoft exchange server
228 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-42897
all versions
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauth
8.1
HIGH
CVE-2026-21527
< 15.02.2562.037
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perf
6.5
MEDIUM
CVE-2025-64667
< 15.02.2562.035
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perf
5.3
MEDIUM
CVE-2025-64666
< 15.02.2562.035
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
7.5
HIGH
CVE-2025-59249
< 15.02.2562.029
Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
8.8
HIGH
CVE-2025-59248
< 15.02.2562.029
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
7.5
HIGH
CVE-2025-53782
< 15.02.2562.029
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privi
8.4
HIGH
CVE-2025-33051
< 15.02.2562.020
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclos
7.5
HIGH
CVE-2025-25007
< 15.02.2562.020
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoo
5.3
MEDIUM
CVE-2025-25006
< 15.02.2562.020
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing o
5.3
MEDIUM
CVE-2025-25005
< 15.02.2562.020
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
6.5
MEDIUM
CVE-2025-53786
all versions
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot
8.0
HIGH
CVE-2024-49040
all versions
Microsoft Exchange Server Spoofing Vulnerability
7.5
HIGH
CVE-2024-26198
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-21410
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
9.8
CRITICAL
CVE-2023-36439
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0
HIGH
CVE-2023-36050
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0
HIGH
CVE-2023-36039
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0
HIGH
CVE-2023-36035
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0
HIGH
CVE-2023-36778
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0
HIGH
CVE-2023-36777
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
5.7
MEDIUM
CVE-2023-36757
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0
HIGH
CVE-2023-36756
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0
HIGH
CVE-2023-36745
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0
HIGH
CVE-2023-36744
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0
HIGH
CVE-2023-38185
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2023-38182
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0
HIGH
CVE-2023-38181
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.8
HIGH
CVE-2023-35388
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0
HIGH
CVE-2023-35368
all versions
Microsoft Exchange Remote Code Execution Vulnerability
8.8
HIGH
CVE-2023-21709
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
9.8
CRITICAL
CVE-2023-32031
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2023-28310
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0
HIGH
CVE-2023-21710
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2023-21707
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2023-21706
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2023-21529
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2023-21764
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2023-21763
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2023-21762
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0
HIGH
CVE-2023-21761
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
7.5
HIGH
CVE-2023-21745
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0
HIGH
CVE-2022-41123
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2022-41080
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2022-41079
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0
HIGH
CVE-2022-41078
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0
HIGH
CVE-2022-41082
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0
HIGH
CVE-2022-41040
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2022-34692
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
5.3
MEDIUM
CVE-2022-30134
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2022-24516
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.0
HIGH
CVE-2022-24477
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.0
HIGH
CVE-2022-21980
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.0
HIGH
CVE-2022-21979
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
4.8
MEDIUM
CVE-2022-21978
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.2
HIGH
CVE-2022-24463
all versions
Microsoft Exchange Server Spoofing Vulnerability
6.5
MEDIUM
CVE-2022-23277
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-21969
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.0
CRITICAL
CVE-2022-21855
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.0
CRITICAL
CVE-2022-21846
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.0
CRITICAL
CVE-2021-42321
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-42305
all versions
Microsoft Exchange Server Spoofing Vulnerability
6.5
MEDIUM
CVE-2021-41349
all versions
Microsoft Exchange Server Spoofing Vulnerability
6.5
MEDIUM
CVE-2021-41350
all versions
Microsoft Exchange Server Spoofing Vulnerability
6.5
MEDIUM
CVE-2021-41348
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.0
HIGH
CVE-2021-34453
all versions
Microsoft Exchange Server Denial of Service Vulnerability
7.5
HIGH
CVE-2021-26427
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.0
CRITICAL
CVE-2021-34523
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
9.0
CRITICAL
CVE-2021-34473
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.1
CRITICAL
CVE-2021-34470
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.0
HIGH
CVE-2021-33768
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.0
HIGH
CVE-2021-33766
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
7.3
HIGH
CVE-2021-31206
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.6
HIGH
CVE-2021-31196
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2021-31209
all versions
Microsoft Exchange Server Spoofing Vulnerability
6.5
MEDIUM
CVE-2021-31207
all versions
Microsoft Exchange Server Security Feature Bypass Vulnerability
6.6
MEDIUM
CVE-2021-31198
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-31195
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
6.5
MEDIUM
CVE-2021-28483
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.0
CRITICAL
CVE-2021-28482
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-28481
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-28480
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2021-27078
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.1
CRITICAL
CVE-2021-27065
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-26858
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-26857
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-26855
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.1
CRITICAL
CVE-2021-26854
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
6.6
MEDIUM
CVE-2021-26412
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.1
CRITICAL
CVE-2021-24085
all versions
Microsoft Exchange Server Spoofing Vulnerability
6.5
MEDIUM
CVE-2021-1730
all versions
<p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor
5.4
MEDIUM
CVE-2020-17144
all versions
Microsoft Exchange Remote Code Execution Vulnerability
8.4
HIGH
CVE-2020-17143
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
8.8
HIGH
CVE-2020-17142
all versions
Microsoft Exchange Remote Code Execution Vulnerability
9.1
CRITICAL
CVE-2020-17141
all versions
Microsoft Exchange Remote Code Execution Vulnerability
8.4
HIGH
CVE-2020-17132
all versions
Microsoft Exchange Remote Code Execution Vulnerability
9.1
CRITICAL
CVE-2020-17117
all versions
Microsoft Exchange Remote Code Execution Vulnerability
6.6
MEDIUM
CVE-2020-17085
all versions
Microsoft Exchange Server Denial of Service Vulnerability
6.2
MEDIUM
CVE-2020-17084
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.5
HIGH
CVE-2020-17083
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
5.5
MEDIUM
CVE-2020-16969
all versions
<p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An at
7.1
HIGH
CVE-2020-16875
all versions
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <
8.4
HIGH
CVE-2020-0903
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted we
5.4
MEDIUM
CVE-2020-0692
all versions
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege
8.1
HIGH
CVE-2020-0688
all versions
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in
8.8
HIGH
CVE-2019-1373
all versions
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Mi
9.8
CRITICAL
CVE-2019-1266
all versions
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka
6.1
MEDIUM
CVE-2019-1233
all versions
A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects
7.5
HIGH
CVE-2019-1137
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted we
5.4
MEDIUM
CVE-2019-1136
all versions
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege
8.1
HIGH
CVE-2019-1084
all versions
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable c
6.5
MEDIUM
CVE-2019-0858
all versions
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests,
6.1
MEDIUM
CVE-2019-0817
all versions
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests,
5.4
MEDIUM
CVE-2019-0724
all versions
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege
8.1
HIGH
CVE-2019-0686
all versions
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege
7.4
HIGH
CVE-2019-0588
all versions
An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view p
6.5
MEDIUM
CVE-2019-0586
all versions
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in
9.8
CRITICAL
CVE-2018-8604
all versions
A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Ser
4.3
MEDIUM
CVE-2018-8581
all versions
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege
7.4
HIGH
CVE-2018-8448
all versions
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web reque
5.4
MEDIUM
CVE-2018-8265
all versions
A remote code execution vulnerability exists in the way Microsoft Exchange software parses specially crafted email messages, aka "
7.8
HIGH
CVE-2018-16793
all versions
Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /ow
8.6
HIGH
CVE-2018-8374
all versions
A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Ser
4.3
MEDIUM
CVE-2018-8302
all versions
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in
9.8
CRITICAL
CVE-2018-8159
all versions
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web reque
5.4
MEDIUM
CVE-2018-8154
all versions
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in
9.8
CRITICAL
CVE-2018-8153
all versions
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests,
5.4
MEDIUM
CVE-2018-8152
all versions
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web reque
5.4
MEDIUM
CVE-2018-8151
all versions
An information disclosure vulnerability exists when Microsoft Exchange improperly handles objects in memory, aka "Microsoft Exchan
4.3
MEDIUM
CVE-2018-0986
all versions
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially craft
8.8
HIGH
CVE-2018-0941
all versions
Microsoft Exchange Server 2016 Cumulative Update 7 and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information dis
5.5
MEDIUM
CVE-2018-0940
all versions
Microsoft Exchange Outlook Web Access (OWA) in Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange
6.5
MEDIUM
CVE-2018-0924
all versions
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exc
6.5
MEDIUM
CVE-2017-11932
all versions
Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook We
8.1
HIGH
CVE-2017-8758
all versions
Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fai
6.1
MEDIUM
CVE-2017-11761
all versions
Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that c
5.3
MEDIUM
CVE-2017-8621
all versions
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an op
6.1
MEDIUM
CVE-2017-8560
all versions
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an el
6.1
MEDIUM
CVE-2017-8559
all versions
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an el
6.1
MEDIUM
CVE-2017-8540
all versions
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2
7.8
HIGH
CVE-2017-8537
all versions
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2
5.5
MEDIUM
CVE-2017-8536
all versions
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2
5.5
MEDIUM
CVE-2017-8535
all versions
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2
5.5
MEDIUM
CVE-2017-0110
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrar
6.1
MEDIUM
CVE-2016-3379
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2 allows remote attackers to in
6.1
MEDIUM
CVE-2016-3378
all versions
Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumu
7.4
HIGH
CVE-2016-0138
all versions
Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Upda
4.3
MEDIUM
CVE-2016-0032
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update
6.1
MEDIUM
CVE-2016-0031
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2016 allows remote attackers to
6.1
MEDIUM
CVE-2016-0030
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update
6.1
MEDIUM
CVE-2016-0029
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2016 allows remote attackers to
6.1
MEDIUM
CVE-2015-2544
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 a
CVE-2015-2543
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 a
CVE-2015-2505
all versions
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sen
CVE-2015-2359
all versions
Cross-site scripting (XSS) vulnerability in the web applications in Microsoft Exchange Server 2013 Cumulative Update 8 allows remo
CVE-2015-1771
all versions
Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Updat
CVE-2015-1764
all versions
The web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allow remote attackers to bypass the Same Origi
CVE-2015-1632
all versions
Cross-site scripting (XSS) vulnerability in errorfe.aspx in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumula
CVE-2015-1631
all versions
Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to spoof meeting organizers via unspecified vec
CVE-2015-1630
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 al
CVE-2015-1629
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 al
CVE-2015-1628
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 al
CVE-2014-6336
all versions
Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens,
CVE-2014-6326
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 allows remote attackers to
CVE-2014-6325
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 allows remote attackers to
CVE-2014-6319
all versions
Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly vali
CVE-2013-5072
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative U
CVE-2013-0418
all versions
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-d
CVE-2012-4791
all versions
Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Informatio
CVE-2010-3937
all versions
Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite lo
CVE-2010-2091
all versions
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle th
CVE-2010-1690
all versions
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier,
CVE-2010-1689
all versions
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier,
CVE-2010-0025
all versions
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange
CVE-2010-0024
all versions
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange
CVE-2009-0099
all versions
The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server
CVE-2009-0098
all versions
Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neu
CVE-2008-1547
all versions
Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build
CVE-2008-2248
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to injec
CVE-2008-2247
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to injec
CVE-2007-0221
all versions
Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of se
CVE-2007-0220
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 a
CVE-2007-0213
all versions
Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows
CVE-2007-0039
all versions
The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 al
CVE-2006-1193
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA),
CVE-2006-0027
all versions
Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted
CVE-2006-0002
all versions
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Offi
CVE-2005-1987
all versions
Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote att
CVE-2005-0563
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote atta
CVE-2005-0738
all versions
Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting
CVE-2005-0560
all versions
Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and
CVE-2005-0044
all versions
The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the l
CVE-2005-0420
all versions
Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login
CVE-2004-0203
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to i
CVE-2004-0840
all versions
The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 200
CVE-2004-0574
all versions
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003,
CVE-2003-0904
all versions
Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP con
CVE-2003-0714
all versions
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory ex
CVE-2003-0712
all versions
Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Ou
CVE-2002-1876
all versions
Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, w
CVE-2002-1873
all versions
Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of serv
CVE-2002-1790
all versions
The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rule
CVE-2002-0698
all versions
Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary co
CVE-2002-0507
all versions
An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication
CVE-2002-0368
all versions
The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail mes
CVE-2002-0055
all versions
SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of se
CVE-2002-0054
all versions
SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle r
CVE-2002-0049
all versions
Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote atta
CVE-2001-0726
all versions
Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inli
CVE-2001-0666
all versions
Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) vi
CVE-2001-0660
<= 5.5
Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresse
CVE-2001-0543
all versions
Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaus
CVE-2001-0509
all versions
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) W
CVE-2001-0340
all versions
An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attacke
CVE-2001-1319
all versions
Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP
CVE-2001-0146
all versions
IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly se
CVE-1999-0945
all versions
Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of s
CVE-2000-1139
all versions
The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attacker
CVE-2000-1006
all versions
Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers
CVE-2000-0524
all versions
Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fie
CVE-2000-0216
all versions
Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tag
CVE-1999-1043
all versions
Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows r
CVE-1999-0993
all versions
Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refr
CVE-1999-0682
all versions
Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-rel
CVE-1999-0385
all versions
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execu
CVE-1999-1322
all versions
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains
CVE-1999-0007
all versions
Information from SSL-encrypted sessions via PKCS #1.
CVE-1999-0284
all versions
Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin