Skip to content

Commit

Permalink
automatic update
Browse files Browse the repository at this point in the history
  • Loading branch information
righel authored and github-actions[bot] committed Oct 21, 2024
1 parent 3c176a9 commit 5f7ed64
Showing 1 changed file with 0 additions and 56 deletions.
56 changes: 0 additions & 56 deletions ms-exchange-versions-cves-dict.json
Original file line number Diff line number Diff line change
Expand Up @@ -6401,28 +6401,12 @@
"id": "CVE-2019-0588",
"last-modified": "2020-08-24T17:37:00",
"summary": "An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka \"Microsoft Exchange Information Disclosure Vulnerability.\" This affects Microsoft Exchange Server."
},
{
"cvss": 4.0,
"cvss-time": "2019-10-03T00:03:00",
"cwe": "NVD-CWE-noinfo",
"id": "CVE-2018-8604",
"last-modified": "2019-10-03T00:03:00",
"summary": "A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka \"Microsoft Exchange Server Tampering Vulnerability.\" This affects Microsoft Exchange Server."
}
]
},
"15.1.1591.13": {
"cpe": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:*",
"cves": [
{
"cvss": 10.0,
"cvss-time": "2020-08-24T17:37:00",
"cwe": "CWE-787",
"id": "CVE-2019-0586",
"last-modified": "2020-08-24T17:37:00",
"summary": "A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka \"Microsoft Exchange Memory Corruption Vulnerability.\" This affects Microsoft Exchange Server."
},
{
"cvss": 7.5,
"cvss-time": "2024-02-15T20:18:00",
Expand Down Expand Up @@ -6470,14 +6454,6 @@
"id": "CVE-2019-0858",
"last-modified": "2020-08-24T17:37:00",
"summary": "A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0817."
},
{
"cvss": 4.0,
"cvss-time": "2020-08-24T17:37:00",
"cwe": "CWE-732",
"id": "CVE-2019-0588",
"last-modified": "2020-08-24T17:37:00",
"summary": "An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka \"Microsoft Exchange Information Disclosure Vulnerability.\" This affects Microsoft Exchange Server."
}
]
},
Expand Down Expand Up @@ -6730,36 +6706,12 @@
"id": "CVE-2019-1266",
"last-modified": "2020-08-24T17:37:00",
"summary": "A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'."
},
{
"cvss": 4.0,
"cvss-time": "2020-05-04T14:14:00",
"cwe": "CWE-200",
"id": "CVE-2019-1084",
"last-modified": "2020-05-04T14:14:00",
"summary": "An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'."
},
{
"cvss": 3.5,
"cvss-time": "2020-04-09T13:19:00",
"cwe": "CWE-79",
"id": "CVE-2019-1137",
"last-modified": "2020-04-09T13:19:00",
"summary": "A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'."
}
]
},
"15.1.1713.9": {
"cpe": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:*",
"cves": [
{
"cvss": 7.8,
"cvss-time": "2020-08-24T17:37:00",
"cwe": "NVD-CWE-noinfo",
"id": "CVE-2019-1233",
"last-modified": "2020-08-24T17:37:00",
"summary": "A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Denial of Service Vulnerability'."
},
{
"cvss": 7.5,
"cvss-time": "2024-02-15T20:18:00",
Expand Down Expand Up @@ -6791,14 +6743,6 @@
"id": "CVE-2021-27065",
"last-modified": "2024-07-25T17:34:00",
"summary": "Microsoft Exchange Server Remote Code Execution Vulnerability"
},
{
"cvss": 4.3,
"cvss-time": "2020-08-24T17:37:00",
"cwe": "CWE-79",
"id": "CVE-2019-1266",
"last-modified": "2020-08-24T17:37:00",
"summary": "A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'."
}
]
},
Expand Down

0 comments on commit 5f7ed64

Please sign in to comment.