Show filters
33 Total Results
Displaying 1-10 of 33
Sort by:
Attacker Value
Very High

CVE-2020-0688 - Exchange Control Panel Viewstate Deserialization Bug

Disclosure Date: February 11, 2020 (last updated February 21, 2025)
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
Attacker Value
Very High

CVE-2021-26857

Disclosure Date: March 03, 2021 (last updated November 28, 2024)
Microsoft Exchange Server Remote Code Execution Vulnerability
5
Attacker Value
Moderate

CVE-2020-17144

Disclosure Date: December 10, 2020 (last updated February 22, 2025)
Microsoft Exchange Remote Code Execution Vulnerability
1
Attacker Value
Very High

CVE-2018-8302

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.
0
Attacker Value
Unknown

CVE-2021-26858

Disclosure Date: March 03, 2021 (last updated November 28, 2024)
Microsoft Exchange Server Remote Code Execution Vulnerability
0
Attacker Value
Unknown

CVE-2019-1084

Disclosure Date: July 15, 2019 (last updated November 27, 2024)
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
0
Attacker Value
Unknown

CVE-2019-1136

Disclosure Date: July 15, 2019 (last updated November 27, 2024)
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
0
Attacker Value
Unknown

CVE-2019-0817

Disclosure Date: April 09, 2019 (last updated November 27, 2024)
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0858.
Attacker Value
Unknown

CVE-2019-0724

Disclosure Date: March 05, 2019 (last updated November 27, 2024)
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0686.
Attacker Value
Unknown

CVE-2019-0686

Disclosure Date: March 05, 2019 (last updated November 27, 2024)
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0724.
0