Filtered by vendor Microsoft Subscriptions
Filtered by product Exchange Server Subscriptions
Total 238 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2001-1099 2 Microsoft, Symantec 2 Exchange Server, Norton Antivirus 2025-04-03 N/A
The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
CVE-2005-0560 1 Microsoft 1 Exchange Server 2025-04-03 N/A
Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.
CVE-2006-0002 1 Microsoft 3 Exchange Server, Office, Outlook 2025-04-03 N/A
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
CVE-2003-0714 1 Microsoft 1 Exchange Server 2025-04-03 N/A
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange 2000.
CVE-1999-1322 2 Broadcom, Microsoft 3 Arcserve Backup, Inoculan, Exchange Server 2025-04-03 N/A
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.
CVE-2006-0027 1 Microsoft 1 Exchange Server 2025-04-03 N/A
Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.
CVE-2002-0507 2 Microsoft, Rsa 2 Exchange Server, Securid 2025-04-03 N/A
An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.
CVE-1999-0682 1 Microsoft 1 Exchange Server 2025-04-03 N/A
Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.
CVE-2002-1873 1 Microsoft 1 Exchange Server 2025-04-03 N/A
Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.
CVE-2001-0509 1 Microsoft 4 Exchange Server, Sql Server, Windows 2000 and 1 more 2025-04-03 N/A
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.
CVE-1999-0385 1 Microsoft 1 Exchange Server 2025-04-03 N/A
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.
CVE-2001-0660 1 Microsoft 1 Exchange Server 2025-04-03 N/A
Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresses by directly accessing a back-end function that processes the global address list (GAL).
CVE-1999-0945 1 Microsoft 1 Exchange Server 2025-04-03 N/A
Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands.
CVE-2021-31198 1 Microsoft 1 Exchange Server 2025-03-01 7.8 High
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2020-0903 1 Microsoft 1 Exchange Server 2025-03-01 5.4 Medium
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.
CVE-2023-21745 1 Microsoft 1 Exchange Server 2025-03-01 8 High
Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-21762 1 Microsoft 1 Exchange Server 2025-03-01 8 High
Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-21707 1 Microsoft 1 Exchange Server 2025-03-01 8.8 High
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-21710 1 Microsoft 1 Exchange Server 2025-03-01 7.2 High
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-28310 1 Microsoft 1 Exchange Server 2025-03-01 8 High
Microsoft Exchange Server Remote Code Execution Vulnerability