Lucene search

K
cveMicrosoftCVE-2006-0002
HistoryJan 10, 2006 - 10:03 p.m.

CVE-2006-0002

2006-01-1022:03:00
microsoft
web.nvd.nist.gov
99
cve-2006-0002
microsoft
outlook
exchange
vulnerability
remote code execution
tnef
mime
security

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.937

Percentile

99.1%

Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.

Affected configurations

Nvd
Node
microsoftexchange_serverMatch5.0-
OR
microsoftexchange_serverMatch5.0sp1
OR
microsoftexchange_serverMatch5.0sp2
OR
microsoftexchange_serverMatch5.5-
OR
microsoftexchange_serverMatch5.5sp1
OR
microsoftexchange_serverMatch5.5sp2
OR
microsoftexchange_serverMatch5.5sp3
OR
microsoftexchange_serverMatch5.5sp4
OR
microsoftexchange_serverMatch2000sp3
OR
microsoftofficeMatch2000sp3
OR
microsoftofficeMatch2003sp1
OR
microsoftofficeMatch2003sp2
OR
microsoftofficeMatchxpsp3
OR
microsoftoutlookMatch2000sp3
OR
microsoftoutlookMatch2002sp3
OR
microsoftoutlookMatch2003
VendorProductVersionCPE
microsoftexchange_server5.0cpe:2.3:a:microsoft:exchange_server:5.0:-:*:*:*:*:*:*
microsoftexchange_server5.0cpe:2.3:a:microsoft:exchange_server:5.0:sp1:*:*:*:*:*:*
microsoftexchange_server5.0cpe:2.3:a:microsoft:exchange_server:5.0:sp2:*:*:*:*:*:*
microsoftexchange_server5.5cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*
microsoftexchange_server5.5cpe:2.3:a:microsoft:exchange_server:5.5:sp1:*:*:*:*:*:*
microsoftexchange_server5.5cpe:2.3:a:microsoft:exchange_server:5.5:sp2:*:*:*:*:*:*
microsoftexchange_server5.5cpe:2.3:a:microsoft:exchange_server:5.5:sp3:*:*:*:*:*:*
microsoftexchange_server5.5cpe:2.3:a:microsoft:exchange_server:5.5:sp4:*:*:*:*:*:*
microsoftexchange_server2000cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*
microsoftoffice2000cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*
Rows per page:
1-10 of 161

References

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.937

Percentile

99.1%