Show filters
33 Total Results
Displaying 11-20 of 33
Sort by:
Attacker Value
Unknown
CVE-2006-6627
Disclosure Date: December 18, 2006 (last updated October 04, 2023)
Integer overflow in the packed PE file parsing implementation in BitDefender products before 20060829, including Antivirus, Antivirus Plus, Internet Security, Mail Protection for Enterprises, and Online Scanner; and BitDefender products for Microsoft ISA Server and Exchange 5.5 through 2003; allows remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow, aka the "cevakrnl.xmd vulnerability."
0
Attacker Value
Unknown
CVE-2006-1193
Disclosure Date: June 13, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
0
Attacker Value
Unknown
CVE-2006-0027
Disclosure Date: May 10, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.
0
Attacker Value
Unknown
CVE-2006-0002
Disclosure Date: January 10, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
0
Attacker Value
Unknown
CVE-2005-1987
Disclosure Date: October 13, 2005 (last updated February 22, 2025)
Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.
0
Attacker Value
Unknown
CVE-2005-0560
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.
0
Attacker Value
Unknown
CVE-2005-0044
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."
0
Attacker Value
Unknown
CVE-2004-0574
Disclosure Date: November 03, 2004 (last updated February 22, 2025)
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.
0
Attacker Value
Unknown
CVE-2003-0714
Disclosure Date: November 17, 2003 (last updated February 22, 2025)
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange 2000.
0
Attacker Value
Unknown
CVE-2002-1876
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.
0