← All CVEs

CVE-2013-3905

medium · 5

Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."

5
CVSS
11.9%
EPSS (exploit prob.)
96th
EPSS percentile
2013-11-13
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
microsoftoutlook2007
microsoftoutlook2010
microsoftoutlook2010
microsoftoutlook2010
microsoftoutlook2010
microsoftoutlook2013
microsoftoutlook2013
microsoftoutlook2013

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-3905