Show filters
260 Total Results
Displaying 211-220 of 260
Sort by:
Attacker Value
Unknown
CVE-2007-0220
Disclosure Date: May 08, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".
0
Attacker Value
Unknown
CVE-2007-0213
Disclosure Date: May 08, 2007 (last updated October 04, 2023)
Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.
0
Attacker Value
Unknown
CVE-2006-6627
Disclosure Date: December 18, 2006 (last updated October 04, 2023)
Integer overflow in the packed PE file parsing implementation in BitDefender products before 20060829, including Antivirus, Antivirus Plus, Internet Security, Mail Protection for Enterprises, and Online Scanner; and BitDefender products for Microsoft ISA Server and Exchange 5.5 through 2003; allows remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow, aka the "cevakrnl.xmd vulnerability."
0
Attacker Value
Unknown
CVE-2006-1193
Disclosure Date: June 13, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
0
Attacker Value
Unknown
CVE-2006-0027
Disclosure Date: May 10, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.
0
Attacker Value
Unknown
CVE-2006-0002
Disclosure Date: January 10, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
0
Attacker Value
Unknown
CVE-2005-4772
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitive files, possibly giving local users the ability to exploit CVE-2005-3013.
0
Attacker Value
Unknown
CVE-2005-3653
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
0
Attacker Value
Unknown
CVE-2005-1987
Disclosure Date: October 13, 2005 (last updated February 22, 2025)
Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.
0
Attacker Value
Unknown
CVE-2005-0563
Disclosure Date: June 14, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL ("javAsc
ript:") in an IMG tag.
0