7.5

CVE-2001-1088

Exploit

Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftOutlook Version97
MicrosoftOutlook Version98
MicrosoftOutlook Version2000
MicrosoftOutlook Express Version4.0
MicrosoftOutlook Express Version4.5
MicrosoftOutlook Express Version4.27.3110
MicrosoftOutlook Express Version4.72.2106
MicrosoftOutlook Express Version4.72.3120.0
MicrosoftOutlook Express Version4.72.3612
MicrosoftOutlook Express Version5.0
MicrosoftOutlook Express Version5.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 35.4% 0.969
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P