CVE-2006-0002

critical

Description

Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.

References

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A624

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1485

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1456

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1316

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1165

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1082

https://exchange.xforce.ibmcloud.com/vulnerabilities/22878

https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-003

http://www.vupen.com/english/advisories/2006/0119

http://www.us-cert.gov/cas/techalerts/TA06-010A.html

http://www.securityfocus.com/bid/16197

http://www.securityfocus.com/archive/1/421520/100/0/threaded

http://www.securityfocus.com/archive/1/421518/100/0/threaded

http://www.kb.cert.org/vuls/id/252146

http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm

http://securitytracker.com/id?1015461

http://securitytracker.com/id?1015460

http://securityreason.com/securityalert/331

http://securityreason.com/securityalert/330

http://secunia.com/advisories/18368

Details

Source: Mitre, NVD

Published: 2006-01-10

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical