Vulnerabilities > Microsoft > Exchange Server
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2001-07-16 | CVE-2001-1319 | Denial of Service vulnerability in Microsoft Exchange 5.5 LDAP Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite. | 5.0 |
2001-06-02 | CVE-2001-0146 | Invalid URL Request DoS vulnerability in Microsoft IIS IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's. | 5.0 |
2001-01-09 | CVE-2000-1139 | USE of Hard-Coded Credentials vulnerability in Microsoft Exchange Server 2000 The installation of Microsoft Exchange 2000 before Rev. | 7.5 |
2000-12-11 | CVE-2000-1006 | Unspecified vulnerability in Microsoft Exchange Server 5.5 Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability. | 5.0 |
2000-06-05 | CVE-2000-0524 | Unspecified vulnerability in Microsoft Exchange Server and Outlook Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From. | 5.0 |
2000-02-29 | CVE-2000-0216 | Unspecified vulnerability in Microsoft Exchange Server, Outlook and Windows Messaging Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list. | 5.0 |
1999-12-31 | CVE-1999-1043 | Unspecified vulnerability in Microsoft Exchange Server 5.0/5.5 Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error). | 5.0 |
1999-12-13 | CVE-1999-0993 | Improper Initialization vulnerability in Microsoft Exchange Server 5.0/5.5 Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed. | 7.5 |
1998-12-01 | CVE-1999-0385 | Classic Buffer Overflow vulnerability in Microsoft Exchange Server 5.5 The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. | 10.0 |
1998-11-12 | CVE-1999-1322 | The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext. | 4.6 |