CVE-2006-0014

Description

Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing certain Unicode strings and modified length values.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
41.401

Associated Vulnerability

VulnerabilityOS Platform
Cumulative Security Update for Outlook Express for Windows Server 2003 (KB911567)Windows
Cumulative Security Update for Outlook Express for Windows XP (KB911567)Windows
Cumulative Security Update for Outlook Express 6 Service Pack 1 (KB911567)Windows
Cumulative Security Update for Outlook Express for Windows Server 2003 SP1 (KB911567)Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234