Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2022-22304

Disclosure Date: July 18, 2022 (last updated October 07, 2023)
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.
Attacker Value
Unknown

CVE-2016-0028

Disclosure Date: June 16, 2016 (last updated November 25, 2024)
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, aka "Microsoft Exchange Information Disclosure Vulnerability."
0
Attacker Value
Unknown

CVE-2014-5359

Disclosure Date: December 16, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in SafeNet Authentication Service (SAS) Outlook Web Access Agent (formerly CRYPTOCard) before 1.03.30109 allows remote attackers to read arbitrary files via a .. (dot dot) in the GetFile parameter to owa/owa.
0
Attacker Value
Unknown

CVE-2010-3213

Disclosure Date: September 07, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule.
0
Attacker Value
Unknown

CVE-2008-2248

Disclosure Date: July 08, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified HTML, a different vulnerability than CVE-2008-2247.
0
Attacker Value
Unknown

CVE-2008-2143

Disclosure Date: May 12, 2008 (last updated October 04, 2023)
Unspecified versions of Microsoft Outlook Web Access (OWA) use the Cache-Control: no-cache HTTP directive instead of no-store, which might cause web browsers that follow RFC-2616 to cache sensitive information.
0
Attacker Value
Unknown

CVE-2005-1052

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
0