Description
Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/20026
Vendor Advisory third-party-advisory
x_refsource_idefense
http://www.idefense.com/application/poi/display?id=227&type=vulnerabilities
Scores
EPSS
0.0938
EPSS Percentile
94.9%
Details
Status
published
Products (2)
microsoft/outlook
2003
microsoft/outlook_web_access
2003
Published
May 02, 2005
Tracked Since
Feb 18, 2026