Vulnerabilities > Microsoft > Exchange Server

DATE CVE VULNERABILITY TITLE RISK
2001-07-16 CVE-2001-1319 Denial of Service vulnerability in Microsoft Exchange 5.5 LDAP
Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.
network
low complexity
microsoft
5.0
2001-06-02 CVE-2001-0146 Invalid URL Request DoS vulnerability in Microsoft IIS
IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
network
low complexity
microsoft
5.0
2001-01-09 CVE-2000-1139 USE of Hard-Coded Credentials vulnerability in Microsoft Exchange Server 2000
The installation of Microsoft Exchange 2000 before Rev.
network
low complexity
microsoft CWE-798
7.5
2000-12-11 CVE-2000-1006 Unspecified vulnerability in Microsoft Exchange Server 5.5
Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability.
network
low complexity
microsoft
5.0
2000-06-05 CVE-2000-0524 Unspecified vulnerability in Microsoft Exchange Server and Outlook
Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.
network
low complexity
microsoft
5.0
2000-02-29 CVE-2000-0216 Unspecified vulnerability in Microsoft Exchange Server, Outlook and Windows Messaging
Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.
network
low complexity
microsoft
5.0
1999-12-31 CVE-1999-1043 Unspecified vulnerability in Microsoft Exchange Server 5.0/5.5
Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).
network
low complexity
microsoft
5.0
1999-12-13 CVE-1999-0993 Improper Initialization vulnerability in Microsoft Exchange Server 5.0/5.5
Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.
network
low complexity
microsoft CWE-665
7.5
1998-12-01 CVE-1999-0385 Classic Buffer Overflow vulnerability in Microsoft Exchange Server 5.5
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.
network
low complexity
microsoft CWE-120
critical
10.0
1998-11-12 CVE-1999-1322 The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.
local
low complexity
broadcom microsoft
4.6