Product:

Lync_server

(Microsoft)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 16
Date Id Summary Products Score Patch Annotated
2019-06-12 CVE-2019-1029 A denial of service vulnerability exists in Skype for Business. An attacker who successfully exploited the vulnerability could cause Skype for Business to stop responding. Note that the denial of service would not allow an attacker to execute code or to elevate the attacker's user rights. To exploit the vulnerability, an attacker needs to obtain a dial-in link for a vulnerable server and then initiates a series of calls within a short amount of time. The update addresses the vulnerability by... Lync_server 5.9
2021-02-25 CVE-2021-24073 Skype for Business and Lync Spoofing Vulnerability Lync_server, Skype_for_business_server N/A
2021-02-25 CVE-2021-24099 Skype for Business and Lync Denial of Service Vulnerability Lync_server, Skype_for_business_server N/A
2021-05-11 CVE-2021-26421 Skype for Business and Lync Spoofing Vulnerability Lync_server, Skype_for_business_server N/A
2021-05-11 CVE-2021-26422 Skype for Business and Lync Remote Code Execution Vulnerability Lync_server, Skype_for_business_server N/A
2022-04-15 CVE-2022-26911 Skype for Business Information Disclosure Vulnerability Lync_server, Skype_for_business_server N/A
2022-07-12 CVE-2022-33633 Skype for Business and Lync Remote Code Execution Vulnerability Lync_server, Skype_for_business N/A
2019-04-09 CVE-2019-0798 A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'. Lync_server, Skype_for_business_server 6.1
2015-09-08 CVE-2015-2536 Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server and Lync Server XSS Elevation of Privilege Vulnerability." Lync_server, Skype_for_business_server N/A
2015-09-08 CVE-2015-2532 Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Lync Server XSS Information Disclosure Vulnerability." Lync_server N/A