VYPR

Exchange Server

by Microsoft

CVEs (259)

  • CVE-2025-25007MedAug 12, 2025
    risk 0.35cvss 5.3epss 0.01

    Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-25006MedAug 12, 2025
    risk 0.35cvss 5.3epss 0.01

    Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2022-34692MedAug 9, 2022
    risk 0.35cvss 5.3epss 0.02

    Microsoft Exchange Server Information Disclosure Vulnerability

  • CVE-2021-1730MedFeb 25, 2021
    risk 0.35cvss 5.4epss 0.02

    A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor to impersonate the user. This update addresses this vulnerability. To prevent these types of attacks, Microsoft recommends customers…

  • CVE-2020-0903MedMar 12, 2020
    risk 0.35cvss 5.4epss 0.02

    A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.

  • CVE-2019-1137MedJul 15, 2019
    risk 0.35cvss 5.4epss 0.02

    A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.

  • CVE-2019-0817MedApr 9, 2019
    risk 0.35cvss 5.4epss 0.02

    A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0858.

  • CVE-2018-8448MedOct 10, 2018
    risk 0.35cvss 5.4epss 0.03

    An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

  • CVE-2018-8159MedMay 9, 2018
    risk 0.35cvss 5.4epss 0.04

    An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

  • CVE-2018-8153MedMay 9, 2018
    risk 0.35cvss 5.4epss 0.04

    A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Spoofing Vulnerability." This affects Microsoft Exchange Server.

  • CVE-2018-8152MedMay 9, 2018
    risk 0.35cvss 5.4epss 0.04

    An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

  • CVE-2017-11761MedSep 13, 2017
    risk 0.35cvss 5.3epss 0.07

    Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability"

  • CVE-2026-45502MedJun 9, 2026
    risk 0.33cvss 5.0epss 0.20

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

  • CVE-2022-21979MedAug 9, 2022
    risk 0.31cvss 4.8epss 0.02

    Microsoft Exchange Server Information Disclosure Vulnerability

  • CVE-2018-8151MedMay 9, 2018
    risk 0.29cvss 4.3epss 0.09

    An information disclosure vulnerability exists when Microsoft Exchange improperly handles objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8154.

  • CVE-2016-0138MedSep 14, 2016
    risk 0.29cvss 4.3epss 0.13

    Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which allows remote authenticated users to obtain sensitive Outlook application…

  • CVE-2018-8604MedDec 12, 2018
    risk 0.28cvss 4.3epss 0.02

    A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server.

  • CVE-2018-8374MedAug 15, 2018
    risk 0.28cvss 4.3epss 0.03

    A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server.

  • CVE-2006-0027May 10, 2006
    risk 0.09cvss —epss 0.79

    Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.

  • CVE-2005-0560May 2, 2005
    risk 0.09cvss —epss 0.69

    Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.

Page 9 of 13