4.3

CVE-2007-2227

The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "Content Disposition Parsing Cross Domain Information Disclosure Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftOutlook Express Version6.0
   MicrosoftWindows 2003 Server Editionx64
   MicrosoftWindows 2003 Server Updatesp2 Editionx64
   MicrosoftWindows 2003 Server Versionsp1
   MicrosoftWindows 2003 Server Versionsp1 Editionitanium
   MicrosoftWindows 2003 Server Versionsp2 Editionitanium
   MicrosoftWindows Xp Editionprofessional_x64
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp2 Editionprofessional_x64
MicrosoftWindows Mail
   MicrosoftWindows Vista Updategold
   MicrosoftWindows Vista Updategold Editionx64
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 50.14% 0.977
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N