CVE Vulnerabilities

CVE-2001-1088

Published: Jun 05, 2001 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the Automatically put people I reply to in my address book option enabled, do not notify the user when the Reply-To address is different than the From address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.

Affected Software

Name Vendor Start Version End Version
Outlook Microsoft 97 (including) 97 (including)
Outlook Microsoft 98 (including) 98 (including)
Outlook Microsoft 2000 (including) 2000 (including)
Outlook_express Microsoft 4.0 (including) 4.0 (including)
Outlook_express Microsoft 4.5 (including) 4.5 (including)
Outlook_express Microsoft 4.27.3110 (including) 4.27.3110 (including)
Outlook_express Microsoft 4.72.2106 (including) 4.72.2106 (including)
Outlook_express Microsoft 4.72.3120.0 (including) 4.72.3120.0 (including)
Outlook_express Microsoft 4.72.3612 (including) 4.72.3612 (including)
Outlook_express Microsoft 5.0 (including) 5.0 (including)
Outlook_express Microsoft 5.5 (including) 5.5 (including)

References