Microsoft
Microsoft Dynamics GP: vulnerabilities and CVEs
Microsoft Dynamics GP has 9 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs9
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23274 | High (8.8) | 2.1% | — | Feb 9, 2022 | Microsoft Dynamics GP Remote Code Execution Vulnerability |
| CVE-2022-23273 | High (8.8) | 2.2% | — | Feb 9, 2022 | Microsoft Dynamics GP Elevation Of Privilege Vulnerability |
| CVE-2022-23272 | High (8.8) | 2.5% | — | Feb 9, 2022 | Microsoft Dynamics GP Elevation Of Privilege Vulnerability |
| CVE-2022-23271 | High (8.8) | 3.8% | — | Feb 9, 2022 | Microsoft Dynamics GP Elevation Of Privilege Vulnerability |
| CVE-2022-23269 | Medium (5.4) | 1.2% | — | Feb 9, 2022 | Microsoft Dynamics GP Spoofing Vulnerability |
| CVE-2010-2083 | Medium (4) | 8.5% | — | May 26, 2010 | Microsoft Dynamics GP has a default value of ACCESS for the system password, which might make it easier for remote authenticated users to bypass intended access restrictions via unspecified vectors. |
| CVE-2010-2011 | Medium (4) | 11% | — | May 21, 2010 | Microsoft Dynamics GP uses a substitution cipher to encrypt the system password field and unspecified other fields, which makes it easier for remote authenticated users to obtain sensitive information by decrypting a… |
| CVE-2006-5266 | High (7.5) | 16% | — | Dec 31, 2006 | Multiple buffer overflows in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allow remote attackers to execute arbitrary code via (1) a crafted Distributed Process Manager (DPM) message to the (a) DPM… |
| CVE-2006-5265 | Medium (5) | 10% | — | Dec 31, 2006 | Unspecified vulnerability in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allows remote attackers to cause a denial of service (crash) via an invalid magic number in a Distributed Process Server (DPS)… |