CVE-2002-0285
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/05/2002
Last modified:
03/04/2025
Description
Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to bypass virus protection and or other filtering mechanisms via a mail message with headers that only contain the CR, which causes Outlook to create separate headers.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:microsoft:outlook_express:5.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:outlook_express:6.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page