7.5

CVE-2001-1088

Exploit
Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Outlook Version 97
Microsoft ≫ Outlook Version 98
Microsoft ≫ Outlook Version 2000
Microsoft ≫ Outlook Express Version 4.0
Microsoft ≫ Outlook Express Version 4.5
Microsoft ≫ Outlook Express Version 4.27.3110
Microsoft ≫ Outlook Express Version 4.72.2106
Microsoft ≫ Outlook Express Version 4.72.3120.0
Microsoft ≫ Outlook Express Version 4.72.3612
Microsoft ≫ Outlook Express Version 5.0
Microsoft ≫ Outlook Express Version 5.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 19.71% 0.971
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://support.microsoft.com/default.aspx?scid=kb%3BEN-US%3Bq234241
http://www.securityfocus.com/archive/1/188752
Vendor Advisory
Exploit
http://www.securityfocus.com/bid/2823
Vendor Advisory
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/6655