← All CVEs

CVE-2006-0002

high · 7.5

Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.

7.5
CVSS
45.6%
EPSS (exploit prob.)
99th
EPSS percentile
2006-01-10
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
microsoftexchange_server5.0
microsoftexchange_server5.0
microsoftexchange_server5.0
microsoftexchange_server5.5
microsoftexchange_server5.5
microsoftexchange_server5.5
microsoftexchange_server5.5
microsoftexchange_server5.5
microsoftexchange_server2000
microsoftoffice2000
microsoftoffice2003
microsoftoffice2003
microsoftofficexp
microsoftoutlook2000
microsoftoutlook2002
microsoftoutlook2003

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-0002