Vulnerabilities > Microsoft > Exchange Server

DATE CVE VULNERABILITY TITLE RISK
2020-12-10 CVE-2020-17142 Unspecified vulnerability in Microsoft Exchange Server 2013/2016/2019
Microsoft Exchange Remote Code Execution Vulnerability
network
low complexity
microsoft
critical
9.1
2020-12-10 CVE-2020-17141 Unspecified vulnerability in Microsoft Exchange Server 2016/2019
Microsoft Exchange Remote Code Execution Vulnerability
network
low complexity
microsoft
8.4
2020-12-10 CVE-2020-17132 Unspecified vulnerability in Microsoft Exchange Server 2013/2016/2019
Microsoft Exchange Remote Code Execution Vulnerability
network
low complexity
microsoft
critical
9.1
2020-12-10 CVE-2020-17117 Unspecified vulnerability in Microsoft Exchange Server 2013/2016/2019
Microsoft Exchange Remote Code Execution Vulnerability
network
high complexity
microsoft
6.6
2020-11-11 CVE-2020-17085 Unspecified vulnerability in Microsoft Exchange Server 2013/2016/2019
Microsoft Exchange Server Denial of Service Vulnerability
network
high complexity
microsoft
6.2
2020-11-11 CVE-2020-17084 Classic Buffer Overflow vulnerability in Microsoft Exchange Server 2013/2016/2019
Microsoft Exchange Server Remote Code Execution Vulnerability
network
high complexity
microsoft CWE-120
8.5
2020-11-11 CVE-2020-17083 Cross-site Scripting vulnerability in Microsoft Exchange Server 2013/2016/2019
Microsoft Exchange Server Remote Code Execution Vulnerability
network
high complexity
microsoft CWE-79
5.5
2020-10-16 CVE-2020-16969 Unspecified vulnerability in Microsoft Exchange Server 2013/2016/2019
<p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages.
network
low complexity
microsoft
7.1
2020-09-11 CVE-2020-16875 Improper Privilege Management vulnerability in Microsoft Exchange Server 2016/2019
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user.
network
low complexity
microsoft CWE-269
8.4
2020-03-12 CVE-2020-0903 Cross-site Scripting vulnerability in Microsoft Exchange Server 2016/2019
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.
network
low complexity
microsoft CWE-79
5.4