Vulnerabilities > Microsoft > Outlook WEB Access > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2016-06-16 | CVE-2016-0028 | Information Exposure vulnerability in Microsoft Outlook web Access Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, aka "Microsoft Exchange Information Disclosure Vulnerability." | 4.3 |
2010-09-07 | CVE-2010-3213 | Cross-Site Request Forgery (CSRF) vulnerability in Microsoft Outlook web Access 2007 Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule. | 6.8 |
2008-07-08 | CVE-2008-2248 | Cross-Site Scripting vulnerability in Microsoft Exchange Server and Outlook web Access Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified HTML, a different vulnerability than CVE-2008-2247. | 4.3 |
2005-05-02 | CVE-2005-1052 | Unspecified vulnerability in Microsoft Outlook and Outlook web Access Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses. | 5.0 |