First published: Wed Sep 12 2001(Updated: )
Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Outlook Express | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2001-0999 is classified as critical due to its potential for remote code execution.
To fix CVE-2001-0999, upgrade to a version of Outlook Express that is not affected, as this vulnerability exists specifically in version 6.0.
CVE-2001-0999 facilitates remote script execution attacks by allowing malicious users to embed SCRIPT tags in plain text email messages.
CVE-2001-0999 affects Microsoft Outlook Express version 6.0.
Yes, CVE-2001-0999 can affect any user running Outlook Express 6.0 on their systems, regardless of the underlying operating system.