Vulnerability Description
Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Outlook Express | 6.0 |
References
- http://www.iss.net/security_center/static/10500.phpExploitPatch
- http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0210&L=ntbugtraq&F=P&S=&ExploitPatchVendor Advisory
- http://www.iss.net/security_center/static/10500.phpExploitPatch
- http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0210&L=ntbugtraq&F=P&S=&ExploitPatchVendor Advisory
FAQ
What is CVE-2002-2202?
CVE-2002-2202 is a vulnerability with a CVSS score of 3.8 (LOW). Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email.
How severe is CVE-2002-2202?
CVE-2002-2202 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-2202?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Outlook Express.