VYPR

Active Directory Federation Services

by Microsoft

CVEs (34)

  • CVE-2015-1757Jun 10, 2015
    risk 0.01cvss —epss 0.11

    Cross-site scripting (XSS) vulnerability in adfs/ls in Active Directory Federation Services (AD FS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 allows remote attackers to inject arbitrary web script or HTML via the wct parameter, aka "ADFS XSS Elevation of…

  • CVE-2015-1638Apr 14, 2015
    risk 0.01cvss —epss 0.13

    Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation, aka "Active Directory Federation Services…

  • CVE-2009-2509Dec 9, 2009
    risk 0.01cvss —epss 0.17

    Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka…

  • CVE-2026-58529HigJul 14, 2026
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

  • CVE-2026-50684MedJul 14, 2026
    risk 0.00cvss 4.8epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-50647HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50411HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50368HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50355HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50324MedJul 14, 2026
    risk 0.00cvss 5.9epss 0.01

    Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50304HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

  • CVE-2026-54983HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50695HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

  • CVE-2009-2508Dec 9, 2009
    risk 0.00cvss —epss 0.01

    The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the…

Page 2 of 2