Active Directory Federation Services
by Microsoft
CVEs (33)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-1638 | 0.01 | — | 0.13 | Apr 14, 2015 | Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation, aka "Active Directory Federation Services… | |||
| CVE-2009-2509 | 0.01 | — | 0.17 | Dec 9, 2009 | Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka… | |||
| CVE-2026-58529 | Hig | 0.00 | 7.1 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-50684 | Med | 0.00 | 4.8 | 0.00 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-50647 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50411 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50368 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50355 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50324 | Med | 0.00 | 5.9 | 0.01 | Jul 14, 2026 | Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50304 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-54983 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50695 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | ||
| CVE-2009-2508 | 0.00 | — | 0.01 | Dec 9, 2009 | The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the… |
- CVE-2015-1638Apr 14, 2015risk 0.01cvss —epss 0.13
Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation, aka "Active Directory Federation Services…
- CVE-2009-2509Dec 9, 2009risk 0.01cvss —epss 0.17
Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka…
- risk 0.00cvss 7.1epss 0.01
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
- risk 0.00cvss 4.8epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 7.5epss 0.01
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 7.5epss 0.01
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 7.5epss 0.01
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 7.5epss 0.01
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 5.9epss 0.01
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 7.5epss 0.01
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 7.5epss 0.01
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 7.5epss 0.01
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
- CVE-2009-2508Dec 9, 2009risk 0.00cvss —epss 0.01
The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the…
Page 2 of 2