← All CVEs

CVE-2003-1378

high · 8.8

Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.

8.8
CVSS
15.6%
EPSS (exploit prob.)
97th
EPSS percentile
2003-12-31
Published

AV:N/AC:M/Au:N/C:C/I:C/A:N

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
microsoftoutlook2000
microsoftoutlook2000
microsoftoutlook2000
microsoftoutlook_express6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2003-1378