Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.
2005-10-13T10:02:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | exchange_server | 2000 | Yes |
Operating System | microsoft | windows_2000 | - | Yes |
Operating System | microsoft | windows_server_2003 | - | Yes |
Operating System | microsoft | windows_server_2003 | - | Yes |
Operating System | microsoft | windows_server_2003 | r2 | Yes |
Operating System | microsoft | windows_server_2003 | sp1 | Yes |
Operating System | microsoft | windows_server_2003 | sp1 | Yes |
Operating System | microsoft | windows_xp | - | Yes |
Operating System | microsoft | windows_xp | - | Yes |
Operating System | microsoft | windows_xp | - | Yes |