CVE-2003-1378
Published Dec 31, 2003
Last updated 7 years ago
Overview
- Description
- Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 8.8
- Impact score
- 9.2
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:outlook:2000:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D52F17AB-2C87-4C1A-91B5-267ABBCF5844" }, { "criteria": "cpe:2.3:a:microsoft:outlook:2000:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A343E57-CF86-4500-96D2-7172B93808BE" }, { "criteria": "cpe:2.3:a:microsoft:outlook:2000:sr1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52A5E941-25A7-405E-B330-8101D6829B43" }, { "criteria": "cpe:2.3:a:microsoft:outlook_express:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85FD3557-956D-4A96-8AA5-5FD9DB87FD11" } ], "operator": "OR" } ] } ]