VulnerabilityModified
CVE-2004-2694
Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE HREF" with the target set to "_top".
MEDIUM 5.8EPSS 8.56%
Does this matter?
Lower severity and a low EPSS score (8.56%). Track it; it rarely justifies an emergency change on its own.
Description
Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE HREF" with the target set to "_top".
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 8.56% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- microsoft/outlook express
- Source
- cve@mitre.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.