Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2006-0002

Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.

  • Published: Jan 10, 2006
  • Updated: Apr 13, 2023
  • CVE: CVE-2006-0002
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

No CWE or OWASP classifications available.

Software From Fixed in
microsoft / exchange_server 5.5-sp1 5.5-sp1.x
microsoft / office 2003-sp1 2003-sp1.x
microsoft / exchange_server 5.5-sp4 5.5-sp4.x
microsoft / office xp-sp3 xp-sp3.x
microsoft / outlook 2000-sp3 2000-sp3.x
microsoft / outlook 2003 2003.x
microsoft / exchange_server 5.5-sp2 5.5-sp2.x
microsoft / office 2003-sp2 2003-sp2.x
microsoft / outlook 2002-sp3 2002-sp3.x
microsoft / exchange_server 2000-sp3 2000-sp3.x
microsoft / exchange_server 5.5-sp3 5.5-sp3.x
microsoft / exchange_server 5.0-sp1 5.0-sp1.x
microsoft / exchange_server 5.0-sp2 5.0-sp2.x
microsoft / office 2000-sp3 2000-sp3.x
microsoft / exchange_server 5.5 5.5.x
microsoft / exchange_server 5.0 5.0.x