CVE-2004-2694

CWE-2645 documents4 sources
Severity
5.8MEDIUM
EPSS
17.4%
top 4.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 29

Description

Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE HREF" with the target set to "_top".

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-w6p4-h264-pgp8: Microsoft Outlook Express 62022-04-29
CVEList
CVE-2004-2694: Microsoft Outlook Express 62007-10-06

💥Exploits & PoCs

2
Exploit-DB
WinAce 2.6.0.5 - Temporary File Parsing Buffer Overflow2005-08-19
Exploit-DB
Linux Kernel 2.4.23/2.6.0 - 'do_mremap()' Bound Checking Validator (2)2004-01-07