CVE-2008-5424Infinite Loop in Microsoft Outlook Express

3 documents3 sources
Severity
4.3MEDIUMNVD
CNA5.0
EPSS
28.8%
top 3.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 14

Description

The MimeOleClearDirtyTree function in InetComm.dll in Microsoft Outlook Express 6.00.2900.5512 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (infinite loop) via a large e-mail message, a related issue to CVE-2006-1173.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDmicrosoft/outlook_express6.00.2900.5512

🔴Vulnerability Details

2
GHSA
GHSA-phxj-wq6j-j348: The MimeOleClearDirtyTree function in InetComm2022-05-14
CVEList
CVE-2008-5424: The MimeOleClearDirtyTree function in InetComm2008-12-11
CVE-2008-5424 — Infinite Loop in Microsoft | cvebase