Lucene search

K
cve[email protected]CVE-2005-1987
HistoryOct 13, 2005 - 10:02 a.m.

CVE-2005-1987

2005-10-1310:02:00
CWE-120
web.nvd.nist.gov
23
cve-2005-1987
buffer overflow
collaboration data objects
cdo
microsoft windows
microsoft exchange server
remote code execution
email security

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.901 High

EPSS

Percentile

98.8%

Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the “Content-Type” string.

Affected configurations

NVD
Node
microsoftexchange_serverMatch2000sp3
Node
microsoftwindows_2000Match-sp4fr
OR
microsoftwindows_server_2003Match-itanium
OR
microsoftwindows_server_2003Match-x64
OR
microsoftwindows_server_2003Matchr2
OR
microsoftwindows_server_2003Matchsp1
OR
microsoftwindows_server_2003Matchsp1itanium
OR
microsoftwindows_xpMatch-x64
OR
microsoftwindows_xpMatch-sp1tablet_pc
OR
microsoftwindows_xpMatch-sp2tablet_pc

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

Low

0.901 High

EPSS

Percentile

98.8%