Lucene search

K
cveMitreCVE-2001-1099
HistoryJun 25, 2002 - 4:00 a.m.

CVE-2001-1099

2002-06-2504:00:00
CWE-434
mitre
web.nvd.nist.gov
31
cve-2001-1099
norton antivirus
microsoft exchange 2000
remote attack
email security

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

44.0%

The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient’s INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.

Affected configurations

Nvd
Node
symantecnorton_antivirusMatch2.5
AND
microsoftexchange_serverMatch2000-
OR
microsoftexchange_serverMatch2000sp1
VendorProductVersionCPE
symantecnorton_antivirus2.5cpe:2.3:a:symantec:norton_antivirus:2.5:*:*:*:*:*:*:*
microsoftexchange_server2000cpe:2.3:a:microsoft:exchange_server:2000:-:*:*:*:*:*:*
microsoftexchange_server2000cpe:2.3:a:microsoft:exchange_server:2000:sp1:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

44.0%

Related for CVE-2001-1099