Количество 8
Количество 8

BDU:2019-02664
Уязвимость почтового сервера Microsoft Exchange Server, программ мгновенного обмена сообщениями Microsoft Lync и Skype for Business, почтового клиента Microsoft Outlook и Outlook for iOS, пакетов программ Microsoft Office и Office 365, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

CVE-2019-1084
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.

CVE-2019-1084
Microsoft Exchange Information Disclosure Vulnerability
GHSA-r2c7-qvrq-pwg6
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.

CVE-2021-27065
Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-26858
Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-26857
Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-26855
Microsoft Exchange Server Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | BDU:2019-02664 Уязвимость почтового сервера Microsoft Exchange Server, программ мгновенного обмена сообщениями Microsoft Lync и Skype for Business, почтового клиента Microsoft Outlook и Outlook for iOS, пакетов программ Microsoft Office и Office 365, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию | CVSS3: 3.5 | 6% Низкий | около 6 лет назад |
![]() | CVE-2019-1084 An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'. | CVSS3: 6.5 | 6% Низкий | около 6 лет назад |
![]() | CVE-2019-1084 Microsoft Exchange Information Disclosure Vulnerability | 6% Низкий | около 6 лет назад | |
GHSA-r2c7-qvrq-pwg6 An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'. | 6% Низкий | больше 3 лет назад | ||
![]() | CVE-2021-27065 Microsoft Exchange Server Remote Code Execution Vulnerability | CVSS3: 7.8 | 94% Критический | больше 4 лет назад |
![]() | CVE-2021-26858 Microsoft Exchange Server Remote Code Execution Vulnerability | CVSS3: 7.8 | 53% Средний | больше 4 лет назад |
![]() | CVE-2021-26857 Microsoft Exchange Server Remote Code Execution Vulnerability | CVSS3: 7.8 | 8% Низкий | больше 4 лет назад |
![]() | CVE-2021-26855 Microsoft Exchange Server Remote Code Execution Vulnerability | CVSS3: 9.1 | 94% Критический | больше 4 лет назад |
Уязвимостей на страницу