Lucene search

K
cveMicrosoftCVE-2007-3897
HistoryOct 09, 2007 - 10:17 p.m.

CVE-2007-3897

2007-10-0922:17:00
CWE-119
microsoft
web.nvd.nist.gov
35
cve-2007-3897
buffer overflow
microsoft outlook express
windows mail
nntp
remote code execution

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.951

Percentile

99.4%

Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption.

Affected configurations

Nvd
Node
microsoftoutlook_expressRange6.0
OR
microsoftoutlook_expressMatch6.0sp1
OR
microsoftwindows_mailMatch-vista
VendorProductVersionCPE
microsoftoutlook_express*cpe:2.3:a:microsoft:outlook_express:*:*:*:*:*:*:*:*
microsoftoutlook_express6.0cpe:2.3:a:microsoft:outlook_express:6.0:sp1:*:*:*:*:*:*
microsoftwindows_mail-cpe:2.3:a:microsoft:windows_mail:-:*:*:*:*:vista:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.951

Percentile

99.4%