
CVE-2018-8581 – Microsoft Exchange Server Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2018-8581
14 Nov 2018 — An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. Existe una vulnerabilidad de elevación de privilegios en Microsoft Exchange Server. Esto también se conoce como "Microsoft Exchange Server Elevation of Privilege Vulnerability". Esto afecta a Microsoft Exchange Server. • https://github.com/WyAtu/CVE-2018-8581 •

CVE-2018-16793 – Rollup 18 for Microsoft Exchange Server 2010 SP3 Server-Side Request Forgery
https://notcve.org/view.php?id=CVE-2018-16793
18 Sep 2018 — Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page. Rollup 18 para Microsoft Exchange Server 2010 SP3 y versiones anteriores tiene una vulnerabilidad Server-Side Request Forgery (SSRF) mediante el parámetro username en /owa/auth/logon.aspx la página de inicio de sesión de OWA (Outlook Web Access). Rollup 18 for Microsoft Exchange Server 2010 SP3 suffers from a server-si... • http://packetstormsecurity.com/files/149411/Rollup-18-For-Microsoft-Exchange-Server-2010-SP3-Server-Side-Request-Forgery.html • CWE-918: Server-Side Request Forgery (SSRF) •

CVE-2018-8302 – Microsoft Exchange Server Voicemail Transcription Improper Access Control Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-8302
14 Aug 2018 — A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. Existe una vulnerabilidad de ejecución remota de código en el software de Microsoft Exchange cuando no gestiona correctamente objetos en la memoria. Esto también se conoce como "Microsoft Exchange Memory Corruption Vulnerability". Esto afecta a Microsoft Exchange Server. • http://www.securityfocus.com/bid/104973 • CWE-787: Out-of-bounds Write •

CVE-2018-8151
https://notcve.org/view.php?id=CVE-2018-8151
09 May 2018 — An information disclosure vulnerability exists when Microsoft Exchange improperly handles objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8154. Existe una vulnerabilidad de divulgación de información cuando Microsoft Exchange gestiona incorrectamente los objetos en la memoria. Esto también se conoce como "Microsoft Exchange Memory Corruption Vulnerability". • http://www.securityfocus.com/bid/104042 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2018-8154 – Microsoft Security Bulletin CVE Revision Increment for September, 2018
https://notcve.org/view.php?id=CVE-2018-8154
09 May 2018 — A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151. Existe una vulnerabilidad de ejecución remota de código en el software de Microsoft Exchange cuando no gestiona correctamente objetos en la memoria. Esto también se conoce como "Microsoft Exchange Memory Corruption Vulnerability". • http://www.securityfocus.com/bid/104054 • CWE-787: Out-of-bounds Write •

CVE-2018-0924
https://notcve.org/view.php?id=CVE-2018-0924
14 Mar 2018 — Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how URL redirects are handled, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0941. Mi... • http://www.securityfocus.com/bid/103320 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2018-0940
https://notcve.org/view.php?id=CVE-2018-0940
14 Mar 2018 — Microsoft Exchange Outlook Web Access (OWA) in Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allows an elevation of privilege vulnerability due to how links in the body of an email message are rewritten, aka "Microsoft Exchange Elevat... • http://www.securityfocus.com/bid/103323 •

CVE-2017-8621
https://notcve.org/view.php?id=CVE-2017-8621
11 Jul 2017 — Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnerability that could lead to spoofing, aka "Microsoft Exchange Open Redirect Vulnerability". Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16 y Exchange Server 2016 CU5, permiten una vulnerabilidad de redireccionamiento abierto que podría conllevar a suplantación, también se conoce como "Microsoft Exchange Open Redirect Vulne... • http://www.securityfocus.com/bid/99533 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2017-8535 – Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
https://notcve.org/view.php?id=CVE-2017-8535
26 May 2017 — The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerability than CVE... • https://packetstorm.news/files/id/142713 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-369: Divide By Zero CWE-476: NULL Pointer Dereference CWE-674: Uncontrolled Recursion •

CVE-2017-8536 – Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
https://notcve.org/view.php?id=CVE-2017-8536
26 May 2017 — The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerability than CVE... • https://packetstorm.news/files/id/142713 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-369: Divide By Zero CWE-476: NULL Pointer Dereference CWE-674: Uncontrolled Recursion •