Buffer Overrun in Exchange Server SMTP Service
New
A security flaw in Microsoft Exchange Server 5.5 could allow a remote attacker to run the code of their choice on the server by exploiting a buffer overrun in the SMTP service.
A security flaw in Microsoft Exchange Server 5.5 could allow a remote attacker to run the code of their choice on the server by exploiting a buffer overrun in the SMTP service.
Malformed Mail Attribute Exhausts Resources
New
A security vulnerability exists in the way Exchange 2000 handles certain malformed RFC message attributes on received mail which could allow a malicious user to launch a denial of service attack.
A security vulnerability exists in the way Exchange 2000 handles certain malformed RFC message attributes on received mail which could allow a malicious user to launch a denial of service attack.
Exchange System Attendant Incorrectly Sets Remote Registry Permissions
New
A security flaw exists in the Microsoft Exchange 2000 System Attendant which could allow an unprivileged user to remotely access registry configuration information on the server.
A security flaw exists in the Microsoft Exchange 2000 System Attendant which could allow an unprivileged user to remotely access registry configuration information on the server.
HTML Script Can Execute in Outlook Web Access
New
A security vulnerability exists in Outlook Web Access (OWA) which may allow inline scripts in HTML mail messages to be executed when opened using Internet Explorer.
A security vulnerability exists in Outlook Web Access (OWA) which may allow inline scripts in HTML mail messages to be executed when opened using Internet Explorer.
Denial of Service Using Invalid Outlook Web Access Request
New
A security vulnerability exists in Exchange 2000 Outlook Web Access which could allow a remote user to cause a denial of service attack by issuing a GET request for an invalid URL that contains a large number of invalid nested folders.
A security vulnerability exists in Exchange 2000 Outlook Web Access which could allow a remote user to cause a denial of service attack by issuing a GET request for an invalid URL that contains a large number of invalid nested folders.
Unauthenticated Users Can View the Global Address List
New
An information disclosure vulnerability exists in the Exchange Server 5.5 Outlook Web Access (OWA) service that could allow an Internet-based attacker to learn the e-mail addresses of users on the server.
An information disclosure vulnerability exists in the Exchange Server 5.5 Outlook Web Access (OWA) service that could allow an Internet-based attacker to learn the e-mail addresses of users on the server.
Incorrect Attachment Handling in Exchange OWA Can Execute Script
New
A security vulnerability exists is Outlook Web Access which could allow a malicious user to run the code of their choice.
A security vulnerability exists is Outlook Web Access which could allow a malicious user to run the code of their choice.
Exchange User Account Vulnerability
A security vulnerability exists in Microsoft® Exchange 2000 Server and Exchange 2000 Enterprise Server which could potentially allow an unauthorized user to remotely login to an Exchange 2000 server and possibly other servers on the affected computer’s network.
A security vulnerability exists in Microsoft® Exchange 2000 Server and Exchange 2000 Enterprise Server which could potentially allow an unauthorized user to remotely login to an Exchange 2000 server and possibly other servers on the affected computer’s network.
Malformed MIME Header Vulnerability
A security vulnerability exists in Microsoft® Exchange Server 5.5 which could enable a malicious user to cause an Exchange server to fail.
A security vulnerability exists in Microsoft® Exchange Server 5.5 which could enable a malicious user to cause an Exchange server to fail.
Malformed IMAP Request Vulnerability
Due to a vulnerability in the Microsoft® Commercial Internet System (MCIS) Mail server a buffer overflow in the IMAP service could allow a malicious user to remotely cause services on the server to fail, or cause arbitrary code to run on the server.
Due to a vulnerability in the Microsoft® Commercial Internet System (MCIS) Mail server a buffer overflow in the IMAP service could allow a malicious user to remotely cause services on the server to fail, or cause arbitrary code to run on the server.
Encapsulated SMTP Address Vulnerability
A security vulnerability exists in Microsoft® Exchange® Server which could allow an attacker to perform mail relaying via an Exchange server that is configured to act as a gateway for other Exchange sites, using the Internet Messaging Service.
A security vulnerability exists in Microsoft® Exchange® Server which could allow an attacker to perform mail relaying via an Exchange server that is configured to act as a gateway for other Exchange sites, using the Internet Messaging Service.
Malformed Bind Request Vulnerability
A vulnerability exists in the LDAP Bind function for Exchange 5.5. The vulnerability could allow denial of service attacks against an Exchange server or, under certain conditions, could allow arbitrary code to be run on the server.
A vulnerability exists in the LDAP Bind function for Exchange 5.5. The vulnerability could allow denial of service attacks against an Exchange server or, under certain conditions, could allow arbitrary code to be run on the server.
Exchange Server SMTP and NNTP Denial-of-Service Vulnerabilities
Due to improper bounds checking in certain SMTP and NNTP authentication command sequences a buffer overflow exists in Microsoft® Exchange Server 5.5 and 5.0. Which if exploited by a malicious attacker could cause specific Exchange services to stop responding.
Due to improper bounds checking in certain SMTP and NNTP authentication command sequences a buffer overflow exists in Microsoft® Exchange Server 5.5 and 5.0. Which if exploited by a malicious attacker could cause specific Exchange services to stop responding.















