Vulnerability Description
Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Outlook | 98 |
| Microsoft | Outlook Express | 5.0 |
References
- http://www.atstake.com/research/advisories/2001/a022301-1.txtPatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-01
- http://www.atstake.com/research/advisories/2001/a022301-1.txtPatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-01
FAQ
What is CVE-2001-0145?
CVE-2001-0145 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.
How severe is CVE-2001-0145?
CVE-2001-0145 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0145?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Outlook, Microsoft Outlook Express.