VYPR

Exchange Server

by Microsoft

CVEs (259)

  • CVE-2001-0340Jul 21, 2001
    risk 0.01cvss —epss 0.06

    An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.

  • CVE-2000-1006Dec 11, 2000
    risk 0.01cvss —epss 0.15

    Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability.

  • CVE-2000-0524Jun 5, 2000
    risk 0.01cvss —epss 0.15

    Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.

  • CVE-1999-1043Dec 31, 1999
    risk 0.01cvss —epss 0.13

    Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).

  • CVE-1999-0993Dec 13, 1999
    risk 0.01cvss —epss 0.07

    Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.

  • CVE-1999-0385Dec 1, 1998
    risk 0.01cvss —epss 0.18

    The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.

  • CVE-1999-0007Jun 26, 1998
    risk 0.01cvss —epss 0.08

    Information from SSL-encrypted sessions via PKCS #1.

  • CVE-2026-55009HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.03

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55008CriJul 14, 2026
    risk 0.00cvss 9.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-55006HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55005HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

  • CVE-2015-1771Jun 10, 2015
    risk 0.00cvss —epss 0.06

    Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users, aka "Exchange Cross-Site Request Forgery Vulnerability."

  • CVE-2005-0738May 2, 2005
    risk 0.00cvss —epss 0.05

    Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a…

  • CVE-2002-1876Dec 31, 2002
    risk 0.00cvss —epss 0.05

    Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.

  • CVE-2002-0507Aug 12, 2002
    risk 0.00cvss —epss 0.02

    An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually…

  • CVE-2001-0666Oct 30, 2001
    risk 0.00cvss —epss 0.02

    Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.

  • CVE-2000-1139Jan 9, 2001
    risk 0.00cvss —epss 0.05

    The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.

  • CVE-2000-0216Feb 29, 2000
    risk 0.00cvss —epss 0.05

    Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution…

  • CVE-1999-1322Nov 12, 1998
    risk 0.00cvss —epss 0.01

    The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.

Page 13 of 13