- EPSS 5.14%
- Veröffentlicht 11.12.2014 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requests, which allows remote attackers to spoof the origin of e-mail messages via unspecified vectors, a...
CVE-2013-5072
- EPSS 6.19%
- Veröffentlicht 11.12.2013 00:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerabili...
CVE-2013-0418
- EPSS 25.1%
- Veröffentlicht 17.01.2013 01:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability t...
CVE-2012-4791
- EPSS 36.7%
- Veröffentlicht 12.12.2012 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."
- EPSS 33.66%
- Veröffentlicht 16.12.2010 19:33:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability."
CVE-2010-2091
- EPSS 4.46%
- Veröffentlicht 27.05.2010 19:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive in...
CVE-2010-1689
- EPSS 25.77%
- Veröffentlicht 07.05.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 S...
CVE-2010-1690
- EPSS 20.69%
- Veröffentlicht 07.05.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 S...
- EPSS 40.22%
- Veröffentlicht 14.04.2010 16:00:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (serv...
- EPSS 59.4%
- Veröffentlicht 14.04.2010 16:00:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read frag...