CVE-2001-1099
5
CVSS Score
Medium
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
Link copied!
Description
The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
None
Availability
None
Affected Software Configurations
- a symantec norton_antivirus 2.5 * * * * * * *
- a microsoft exchange_server 2000 - * * * * * *
- a microsoft exchange_server 2000 sp1 * * * * * *
Weaknesses (CWE)
- CWE-434
References & External Links
- http://www.securityfocus.com/archive/1/212724
- http://www.securityfocus.com/archive/1/213762
- http://www.securityfocus.com/bid/3305
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7093
- http://www.securityfocus.com/archive/1/212724
- http://www.securityfocus.com/archive/1/213762
- http://www.securityfocus.com/bid/3305
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7093
External Resources
CVE History Timeline
Jan 01, 2004 05:00
Initial Analysis
Oct 10, 2017 01:30
CVE Modified
Apr 02, 2020 12:51
Modified Analysis
May 14, 2024 01:19
CVE Modified
Nov 20, 2024 23:36
CVE Modified