Exchange 2000
by Microsoft
CVEs (23)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-0688 | Hig | 0.86 | 8.8 | 1.00 | KEV | Feb 11, 2020 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'. | |
| CVE-2020-17144 | Hig | 0.70 | 8.4 | 0.37 | KEV | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability | |
| CVE-2020-17132 | Cri | 0.69 | 9.1 | 0.90 | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability | ||
| CVE-2019-1373 | Cri | 0.65 | 9.8 | 0.18 | Nov 12, 2019 | A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'. | ||
| CVE-2020-17142 | Cri | 0.59 | 9.1 | 0.03 | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability | ||
| CVE-2023-35368 | Hig | 0.57 | 8.8 | 0.04 | Aug 8, 2023 | Microsoft Exchange Remote Code Execution Vulnerability | ||
| CVE-2020-17141 | Hig | 0.55 | 8.4 | 0.07 | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability | ||
| CVE-2020-17117 | Med | 0.47 | 6.6 | 0.49 | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability | ||
| CVE-2020-16969 | Hig | 0.46 | 7.1 | 0.03 | Oct 16, 2020 | An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user. To exploit the vulnerability, an… | ||
| CVE-2019-1084 | Med | 0.43 | 6.5 | 0.05 | Jul 15, 2019 | An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to… | ||
| CVE-2006-0027 | 0.09 | — | 0.79 | May 10, 2006 | Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties. | |||
| CVE-2003-0714 | 0.09 | — | 0.76 | Nov 17, 2003 | The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange… | |||
| CVE-2002-0055 | 0.03 | — | 0.35 | Mar 8, 2002 | SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request. | |||
| CVE-2001-0146 | 0.03 | — | 0.35 | Jun 2, 2001 | IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's. | |||
| CVE-2001-1319 | 0.02 | — | 0.29 | Jul 16, 2001 | Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite. | |||
| CVE-2003-0904 | 0.01 | — | 0.08 | Jan 20, 2004 | Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g.… | |||
| CVE-2002-1873 | 0.01 | — | 0.14 | Dec 31, 2002 | Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls. | |||
| CVE-2002-0368 | 0.01 | — | 0.15 | Jun 18, 2002 | The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources." | |||
| CVE-1999-0993 | 0.01 | — | 0.07 | Dec 13, 1999 | Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed. | |||
| CVE-2026-26137 | 0.00 | — | 0.01 | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. |
- risk 0.86cvss 8.8epss 1.00
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
- risk 0.70cvss 8.4epss 0.37
Microsoft Exchange Remote Code Execution Vulnerability
- risk 0.69cvss 9.1epss 0.90
Microsoft Exchange Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.18
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.
- risk 0.59cvss 9.1epss 0.03
Microsoft Exchange Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.04
Microsoft Exchange Remote Code Execution Vulnerability
- risk 0.55cvss 8.4epss 0.07
Microsoft Exchange Remote Code Execution Vulnerability
- risk 0.47cvss 6.6epss 0.49
Microsoft Exchange Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.03
An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user. To exploit the vulnerability, an…
- risk 0.43cvss 6.5epss 0.05
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to…
- CVE-2006-0027May 10, 2006risk 0.09cvss —epss 0.79
Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.
- CVE-2003-0714Nov 17, 2003risk 0.09cvss —epss 0.76
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange…
- CVE-2002-0055Mar 8, 2002risk 0.03cvss —epss 0.35
SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
- CVE-2001-0146Jun 2, 2001risk 0.03cvss —epss 0.35
IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
- CVE-2001-1319Jul 16, 2001risk 0.02cvss —epss 0.29
Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.
- CVE-2003-0904Jan 20, 2004risk 0.01cvss —epss 0.08
Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g.…
- CVE-2002-1873Dec 31, 2002risk 0.01cvss —epss 0.14
Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.
- CVE-2002-0368Jun 18, 2002risk 0.01cvss —epss 0.15
The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."
- CVE-1999-0993Dec 13, 1999risk 0.01cvss —epss 0.07
Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.
- CVE-2026-26137Mar 19, 2026risk 0.00cvss —epss 0.01
Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.
Page 1 of 2