First published: Wed Dec 22 1999(Updated: )
Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =4.5 | |
Microsoft Outlook Express | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2000-0036 is considered medium due to the risk of unauthorized file downloads.
To fix CVE-2000-0036, users should upgrade to a patched version of Outlook Express or Internet Explorer that addresses this vulnerability.
CVE-2000-0036 allows attackers to exploit Outlook Express to download attachments without user consent, potentially leading to malware infection.
Users of Outlook Express version 5.0 for Mac OS and Internet Explorer version 4.5 for Macintosh are affected by CVE-2000-0036.
A possible workaround for CVE-2000-0036 includes disabling HTML mail or using an alternative email client until the software can be updated.