Описание
Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.
Ссылки
- Broken Link
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryUS Government Resource
- Broken Link
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryUS Government Resource
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Broken Link
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*
Конфигурация 2
Одно из
cpe:2.3:o:microsoft:windows_2000:-:sp4:*:fr:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:-:*:*:*:*:*:itanium:*
cpe:2.3:o:microsoft:windows_server_2003:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2003:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:sp1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:sp1:*:*:*:*:*:itanium:*
cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_xp:-:sp1:*:*:tablet_pc:*:*:*
cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:tablet_pc:*:*:*
EPSS
Процентиль: 98%
0.57021
Средний
7.5 High
CVSS2
Дефекты
CWE-120
Связанные уязвимости
github
почти 4 года назад
Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.
EPSS
Процентиль: 98%
0.57021
Средний
7.5 High
CVSS2
Дефекты
CWE-120