CVE Vulnerabilities

CVE-2004-2137

Published: Dec 31, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Outlook Express 6.0, when sending multipart e-mail messages using the Break apart messages larger than setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information.

Affected Software

Name Vendor Start Version End Version
Outlook_express Microsoft 6.0 (including) 6.0 (including)
Outlook_express Microsoft 6.0-sp1 (including) 6.0-sp1 (including)

References