Vulnerabilities > Microsoft > Exchange Server > Medium

DATE CVE VULNERABILITY TITLE RISK
2014-12-11 CVE-2014-6319 Improper Access Control vulnerability in Microsoft Exchange Server 2007/2010/2013
Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requests, which allows remote attackers to spoof the origin of e-mail messages via unspecified vectors, aka "Outlook Web App Token Spoofing Vulnerability."
network
low complexity
microsoft CWE-284
5.0
2013-12-11 CVE-2013-5072 Cross-Site Scripting vulnerability in Microsoft Exchange Server 2010/2013
Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."
network
microsoft CWE-79
4.3
2013-01-17 CVE-2013-0418 Heap Based Buffer Overflow vulnerability in Oracle Outside In Technology
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-0393.
network
microsoft oracle
6.8
2011-10-21 CVE-2011-0290 Permissions, Privileges, and Access Controls vulnerability in RIM Blackberry Enterprise Server 5.0.3
The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact lists, or cause a denial of service (login unavailability), via unspecified vectors.
network
low complexity
rim lotus microsoft CWE-264
6.5
2010-12-16 CVE-2010-3937 Resource Management Errors vulnerability in Microsoft Exchange Server 2007
Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability."
network
low complexity
microsoft CWE-399
4.0
2010-05-27 CVE-2010-2091 Cross-Site Scripting vulnerability in Microsoft Exchange Server 2007
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
network
microsoft CWE-79
4.3
2010-05-07 CVE-2010-1690 Improper Input Validation vulnerability in Microsoft products
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
network
low complexity
microsoft CWE-20
6.4
2010-05-07 CVE-2010-1689 Cryptographic Issues vulnerability in Microsoft products
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
network
low complexity
microsoft CWE-310
6.4
2010-04-14 CVE-2010-0025 Information Exposure vulnerability in Microsoft products
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and then sending a STARTTLS command, aka "SMTP Memory Allocation Vulnerability."
network
low complexity
microsoft CWE-200
5.0
2010-04-14 CVE-2010-0024 Improper Input Validation vulnerability in Microsoft products
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."
network
low complexity
microsoft CWE-20
5.0