CVE Vulnerabilities

CVE-2004-2137

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Outlook Express 6.0, when sending multipart e-mail messages using the Break apart messages larger than setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information.

Affected Software

NameVendorStart VersionEnd Version
Outlook_expressMicrosoft6.0 (including)6.0 (including)
Outlook_expressMicrosoft6.0-sp1 (including)6.0-sp1 (including)

References