Page 45 of 234 results (0.006 seconds)

CVSS: 5.0EPSS: 3%CPEs: 2EXPL: 0

Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite. • http://ciac.llnl.gov/ciac/bulletins/l-116.shtml http://www.cert.org/advisories/CA-2001-18.html http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3 http://www.kb.cert.org/vuls/id/763400 http://www.kb.cert.org/vuls/id/CFCN-4YAQC7 http://www.securityfocus.com/bid/3045 https://exchange.xforce.ibmcloud.com/vulnerabilities/6899 •

CVSS: 5.0EPSS: 9%CPEs: 2EXPL: 0

Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ169174 http://www.ciac.org/ciac/bulletins/i-080.shtml http://xforce.iss.net/alerts/advise4.php https://exchange.xforce.ibmcloud.com/vulnerabilities/1223 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVSS: 5.0EPSS: 1%CPEs: 2EXPL: 0

IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's. • http://www.kb.cert.org/vuls/id/796584 http://www.securityfocus.com/bid/2440 http://www.securityfocus.com/bid/2441 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-014 https://exchange.xforce.ibmcloud.com/vulnerabilities/6171 https://exchange.xforce.ibmcloud.com/vulnerabilities/6172 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability. • http://www.securityfocus.com/bid/1958 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-088 https://exchange.xforce.ibmcloud.com/vulnerabilities/5537 • CWE-798: Use of Hard-coded Credentials •

CVSS: 5.0EPSS: 74%CPEs: 1EXPL: 1

Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability. • http://www.securityfocus.com/bid/1869 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-082 https://exchange.xforce.ibmcloud.com/vulnerabilities/5448 •