Home/Product/microsoft exchange server
Product

microsoft exchange server

228 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-42897
all versions
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauth
8.1HIGH
CVE-2026-21527
< 15.02.2562.037
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perf
6.5MEDIUM
CVE-2025-64667
< 15.02.2562.035
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perf
5.3MEDIUM
CVE-2025-64666
< 15.02.2562.035
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
7.5HIGH
CVE-2025-59249
< 15.02.2562.029
Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
8.8HIGH
CVE-2025-59248
< 15.02.2562.029
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
7.5HIGH
CVE-2025-53782
< 15.02.2562.029
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privi
8.4HIGH
CVE-2025-33051
< 15.02.2562.020
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclos
7.5HIGH
CVE-2025-25007
< 15.02.2562.020
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoo
5.3MEDIUM
CVE-2025-25006
< 15.02.2562.020
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing o
5.3MEDIUM
CVE-2025-25005
< 15.02.2562.020
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
6.5MEDIUM
CVE-2025-53786
all versions
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot
8.0HIGH
CVE-2024-49040
all versions
Microsoft Exchange Server Spoofing Vulnerability
7.5HIGH
CVE-2024-26198
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8HIGH
CVE-2024-21410
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
9.8CRITICAL
CVE-2023-36439
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0HIGH
CVE-2023-36050
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0HIGH
CVE-2023-36039
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0HIGH
CVE-2023-36035
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0HIGH
CVE-2023-36778
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0HIGH
CVE-2023-36777
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
5.7MEDIUM
CVE-2023-36757
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0HIGH
CVE-2023-36756
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0HIGH
CVE-2023-36745
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0HIGH
CVE-2023-36744
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0HIGH
CVE-2023-38185
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8HIGH
CVE-2023-38182
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0HIGH
CVE-2023-38181
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.8HIGH
CVE-2023-35388
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0HIGH
CVE-2023-35368
all versions
Microsoft Exchange Remote Code Execution Vulnerability
8.8HIGH
CVE-2023-21709
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
9.8CRITICAL
CVE-2023-32031
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8HIGH
CVE-2023-28310
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0HIGH
CVE-2023-21710
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.2HIGH
CVE-2023-21707
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8HIGH
CVE-2023-21706
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8HIGH
CVE-2023-21529
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8HIGH
CVE-2023-21764
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
7.8HIGH
CVE-2023-21763
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
7.8HIGH
CVE-2023-21762
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0HIGH
CVE-2023-21761
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
7.5HIGH
CVE-2023-21745
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0HIGH
CVE-2022-41123
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-41080
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.8HIGH
CVE-2022-41079
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0HIGH
CVE-2022-41078
all versions
Microsoft Exchange Server Spoofing Vulnerability
8.0HIGH
CVE-2022-41082
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.0HIGH
CVE-2022-41040
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.8HIGH
CVE-2022-34692
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
5.3MEDIUM
CVE-2022-30134
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
6.5MEDIUM
CVE-2022-24516
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.0HIGH
CVE-2022-24477
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.0HIGH
CVE-2022-21980
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.0HIGH
CVE-2022-21979
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
4.8MEDIUM
CVE-2022-21978
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.2HIGH
CVE-2022-24463
all versions
Microsoft Exchange Server Spoofing Vulnerability
6.5MEDIUM
CVE-2022-23277
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8HIGH
CVE-2022-21969
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.0CRITICAL
CVE-2022-21855
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.0CRITICAL
CVE-2022-21846
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.0CRITICAL
CVE-2021-42321
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8HIGH
CVE-2021-42305
all versions
Microsoft Exchange Server Spoofing Vulnerability
6.5MEDIUM
CVE-2021-41349
all versions
Microsoft Exchange Server Spoofing Vulnerability
6.5MEDIUM
CVE-2021-41350
all versions
Microsoft Exchange Server Spoofing Vulnerability
6.5MEDIUM
CVE-2021-41348
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.0HIGH
CVE-2021-34453
all versions
Microsoft Exchange Server Denial of Service Vulnerability
7.5HIGH
CVE-2021-26427
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.0CRITICAL
CVE-2021-34523
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
9.0CRITICAL
CVE-2021-34473
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.1CRITICAL
CVE-2021-34470
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.0HIGH
CVE-2021-33768
all versions
Microsoft Exchange Server Elevation of Privilege Vulnerability
8.0HIGH
CVE-2021-33766
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
7.3HIGH
CVE-2021-31206
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.6HIGH
CVE-2021-31196
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.2HIGH
CVE-2021-31209
all versions
Microsoft Exchange Server Spoofing Vulnerability
6.5MEDIUM
CVE-2021-31207
all versions
Microsoft Exchange Server Security Feature Bypass Vulnerability
6.6MEDIUM
CVE-2021-31198
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2021-31195
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
6.5MEDIUM
CVE-2021-28483
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.0CRITICAL
CVE-2021-28482
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.8HIGH
CVE-2021-28481
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.8CRITICAL
CVE-2021-28480
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.8CRITICAL
CVE-2021-27078
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.1CRITICAL
CVE-2021-27065
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2021-26858
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2021-26857
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
7.8HIGH
CVE-2021-26855
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.1CRITICAL
CVE-2021-26854
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
6.6MEDIUM
CVE-2021-26412
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
9.1CRITICAL
CVE-2021-24085
all versions
Microsoft Exchange Server Spoofing Vulnerability
6.5MEDIUM
CVE-2021-1730
all versions
<p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor
5.4MEDIUM
CVE-2020-17144
all versions
Microsoft Exchange Remote Code Execution Vulnerability
8.4HIGH
CVE-2020-17143
all versions
Microsoft Exchange Server Information Disclosure Vulnerability
8.8HIGH
CVE-2020-17142
all versions
Microsoft Exchange Remote Code Execution Vulnerability
9.1CRITICAL
CVE-2020-17141
all versions
Microsoft Exchange Remote Code Execution Vulnerability
8.4HIGH
CVE-2020-17132
all versions
Microsoft Exchange Remote Code Execution Vulnerability
9.1CRITICAL
CVE-2020-17117
all versions
Microsoft Exchange Remote Code Execution Vulnerability
6.6MEDIUM
CVE-2020-17085
all versions
Microsoft Exchange Server Denial of Service Vulnerability
6.2MEDIUM
CVE-2020-17084
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
8.5HIGH
CVE-2020-17083
all versions
Microsoft Exchange Server Remote Code Execution Vulnerability
5.5MEDIUM
CVE-2020-16969
all versions
<p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An at
7.1HIGH
CVE-2020-16875
all versions
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <
8.4HIGH
CVE-2020-0903
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted we
5.4MEDIUM
CVE-2020-0692
all versions
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege
8.1HIGH
CVE-2020-0688
all versions
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in
8.8HIGH
CVE-2019-1373
all versions
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Mi
9.8CRITICAL
CVE-2019-1266
all versions
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka
6.1MEDIUM
CVE-2019-1233
all versions
A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects
7.5HIGH
CVE-2019-1137
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted we
5.4MEDIUM
CVE-2019-1136
all versions
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege
8.1HIGH
CVE-2019-1084
all versions
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable c
6.5MEDIUM
CVE-2019-0858
all versions
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests,
6.1MEDIUM
CVE-2019-0817
all versions
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests,
5.4MEDIUM
CVE-2019-0724
all versions
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege
8.1HIGH
CVE-2019-0686
all versions
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege
7.4HIGH
CVE-2019-0588
all versions
An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view p
6.5MEDIUM
CVE-2019-0586
all versions
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in
9.8CRITICAL
CVE-2018-8604
all versions
A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Ser
4.3MEDIUM
CVE-2018-8581
all versions
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege
7.4HIGH
CVE-2018-8448
all versions
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web reque
5.4MEDIUM
CVE-2018-8265
all versions
A remote code execution vulnerability exists in the way Microsoft Exchange software parses specially crafted email messages, aka "
7.8HIGH
CVE-2018-16793
all versions
Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /ow
8.6HIGH
CVE-2018-8374
all versions
A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Ser
4.3MEDIUM
CVE-2018-8302
all versions
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in
9.8CRITICAL
CVE-2018-8159
all versions
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web reque
5.4MEDIUM
CVE-2018-8154
all versions
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in
9.8CRITICAL
CVE-2018-8153
all versions
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests,
5.4MEDIUM
CVE-2018-8152
all versions
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web reque
5.4MEDIUM
CVE-2018-8151
all versions
An information disclosure vulnerability exists when Microsoft Exchange improperly handles objects in memory, aka "Microsoft Exchan
4.3MEDIUM
CVE-2018-0986
all versions
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially craft
8.8HIGH
CVE-2018-0941
all versions
Microsoft Exchange Server 2016 Cumulative Update 7 and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information dis
5.5MEDIUM
CVE-2018-0940
all versions
Microsoft Exchange Outlook Web Access (OWA) in Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange
6.5MEDIUM
CVE-2018-0924
all versions
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exc
6.5MEDIUM
CVE-2017-11932
all versions
Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook We
8.1HIGH
CVE-2017-8758
all versions
Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fai
6.1MEDIUM
CVE-2017-11761
all versions
Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that c
5.3MEDIUM
CVE-2017-8621
all versions
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an op
6.1MEDIUM
CVE-2017-8560
all versions
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an el
6.1MEDIUM
CVE-2017-8559
all versions
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an el
6.1MEDIUM
CVE-2017-8540
all versions
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2
7.8HIGH
CVE-2017-8537
all versions
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2
5.5MEDIUM
CVE-2017-8536
all versions
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2
5.5MEDIUM
CVE-2017-8535
all versions
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2
5.5MEDIUM
CVE-2017-0110
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrar
6.1MEDIUM
CVE-2016-3379
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2 allows remote attackers to in
6.1MEDIUM
CVE-2016-3378
all versions
Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumu
7.4HIGH
CVE-2016-0138
all versions
Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Upda
4.3MEDIUM
CVE-2016-0032
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update
6.1MEDIUM
CVE-2016-0031
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2016 allows remote attackers to
6.1MEDIUM
CVE-2016-0030
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update
6.1MEDIUM
CVE-2016-0029
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2016 allows remote attackers to
6.1MEDIUM
CVE-2015-2544
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 a
CVE-2015-2543
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 a
CVE-2015-2505
all versions
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sen
CVE-2015-2359
all versions
Cross-site scripting (XSS) vulnerability in the web applications in Microsoft Exchange Server 2013 Cumulative Update 8 allows remo
CVE-2015-1771
all versions
Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Updat
CVE-2015-1764
all versions
The web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allow remote attackers to bypass the Same Origi
CVE-2015-1632
all versions
Cross-site scripting (XSS) vulnerability in errorfe.aspx in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumula
CVE-2015-1631
all versions
Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to spoof meeting organizers via unspecified vec
CVE-2015-1630
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 al
CVE-2015-1629
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 al
CVE-2015-1628
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 al
CVE-2014-6336
all versions
Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens,
CVE-2014-6326
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 allows remote attackers to
CVE-2014-6325
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 allows remote attackers to
CVE-2014-6319
all versions
Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly vali
CVE-2013-5072
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative U
CVE-2013-0418
all versions
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-d
CVE-2012-4791
all versions
Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Informatio
CVE-2010-3937
all versions
Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite lo
CVE-2010-2091
all versions
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle th
CVE-2010-1690
all versions
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier,
CVE-2010-1689
all versions
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier,
CVE-2010-0025
all versions
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange
CVE-2010-0024
all versions
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange
CVE-2009-0099
all versions
The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server
CVE-2009-0098
all versions
Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neu
CVE-2008-1547
all versions
Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build
CVE-2008-2248
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to injec
CVE-2008-2247
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to injec
CVE-2007-0221
all versions
Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of se
CVE-2007-0220
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 a
CVE-2007-0213
all versions
Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows
CVE-2007-0039
all versions
The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 al
CVE-2006-1193
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA),
CVE-2006-0027
all versions
Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted
CVE-2006-0002
all versions
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Offi
CVE-2005-1987
all versions
Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote att
CVE-2005-0563
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote atta
CVE-2005-0738
all versions
Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting
CVE-2005-0560
all versions
Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and
CVE-2005-0044
all versions
The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the l
CVE-2005-0420
all versions
Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login
CVE-2004-0203
all versions
Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to i
CVE-2004-0840
all versions
The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 200
CVE-2004-0574
all versions
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003,
CVE-2003-0904
all versions
Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP con
CVE-2003-0714
all versions
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory ex
CVE-2003-0712
all versions
Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Ou
CVE-2002-1876
all versions
Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, w
CVE-2002-1873
all versions
Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of serv
CVE-2002-1790
all versions
The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rule
CVE-2002-0698
all versions
Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary co
CVE-2002-0507
all versions
An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication
CVE-2002-0368
all versions
The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail mes
CVE-2002-0055
all versions
SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of se
CVE-2002-0054
all versions
SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle r
CVE-2002-0049
all versions
Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote atta
CVE-2001-0726
all versions
Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inli
CVE-2001-0666
all versions
Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) vi
CVE-2001-0660
<= 5.5
Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresse
CVE-2001-0543
all versions
Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaus
CVE-2001-0509
all versions
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) W
CVE-2001-0340
all versions
An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attacke
CVE-2001-1319
all versions
Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP
CVE-2001-0146
all versions
IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly se
CVE-1999-0945
all versions
Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of s
CVE-2000-1139
all versions
The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attacker
CVE-2000-1006
all versions
Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers
CVE-2000-0524
all versions
Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fie
CVE-2000-0216
all versions
Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tag
CVE-1999-1043
all versions
Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows r
CVE-1999-0993
all versions
Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refr
CVE-1999-0682
all versions
Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-rel
CVE-1999-0385
all versions
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execu
CVE-1999-1322
all versions
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains
CVE-1999-0007
all versions
Information from SSL-encrypted sessions via PKCS #1.
CVE-1999-0284
all versions
Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin