Known vulnerabilities in Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20 - page 2

Vendor: Microsoft
Version: 2010 Service Pack 3 Update Rollup 20
Software CPE: cpe:2.3:a:microsoft:microsoft_exchange_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 28
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Microsoft Exchange Server version 2010 Service Pack 3 Update Rollup 20 Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20 is affected by 28 vulnerabilities: 2 high, 25 medium, 1 low Critical High Medium Low

Vulnerabilities (28)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU17611 - Improper input validation
CVE-2018-18224
CWE-20 Medium
No
No
2010 Service Pack 3 Update Rollup 26, 2013 Cumulative Update 22 15.00.1473.003, 2016 Cumulative Update 12 15.01.1713.005, 2019 Cumulative Update 1 15.02.0330.005 12.02.2019 SB2018101715
SB2019021302
#VU17609 - Improper input validation
CVE-2018-18223
CWE-20 Medium
No
No
2010 Service Pack 3 Update Rollup 26, 2013 Cumulative Update 22 15.00.1473.003, 2016 Cumulative Update 12 15.01.1713.005, 2019 Cumulative Update 1 15.02.0330.005 12.02.2019 SB2018101715
SB2019021302
#VU17608 - Improper input validation
CVE-2018-3234
CWE-20 Medium
No
No
2010 Service Pack 3 Update Rollup 26, 2013 Cumulative Update 22 15.00.1473.003, 2016 Cumulative Update 12 15.01.1713.005, 2019 Cumulative Update 1 15.02.0330.005 12.02.2019 SB2018101715
SB2019021302
#VU17588 - Improper Access Control
CVE-2019-0724
CWE-284 Medium
Public exploit available
No
2010 Service Pack 3 Update Rollup 26, 2013 Cumulative Update 22 15.00.1473.003, 2016 Cumulative Update 12 15.01.1713.005, 2019 Cumulative Update 1 15.02.0330.005 12.02.2019 SB2019012701
#VU17228 - Improper Access Control
CVE-2019-0686
CWE-284 Medium
No
No
2010 Service Pack 3 Update Rollup 26, 2013 Cumulative Update 22 15.00.1473.003, 2016 Cumulative Update 12 15.01.1713.005, 2019 Cumulative Update 1 15.02.0330.005 27.01.2019 SB2019012701
#VU14369 - Memory corruption
CVE-2018-8302
CWE-119 High
No
No
- 14.08.2018 SB2018081411
#VU11001 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2018-0924
CWE-601 Low
No
No
- 13.03.2018 SB2018031309
#VU11007 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-0940
CWE-79 Medium
No
No
- 13.03.2018 SB2018031309


Showing elements 21 - 40 out of 28