[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-3905Date: (C)2013-11-19   (M)2023-12-22


Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
MS13-094
TA13-317A
oval:org.mitre.oval:def:19239

CPE    8
cpe:/a:microsoft:outlook:2010:sp2:~~~x86~~
cpe:/a:microsoft:outlook:2013
cpe:/a:microsoft:outlook:2010:sp1:~~~x86~~
cpe:/a:microsoft:outlook:2010:sp2:~~~~x64~
...
CWE    1
CWE-200
OVAL    2
oval:org.secpod.oval:def:15961
oval:org.secpod.oval:def:15962

© SecPod Technologies