CVE-2005-1213

Microsoft Outlook Express <6 SP1 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16379
exploitdb WORKING POC VERIFIED
by eyas · c++remotewindows
https://www.exploit-db.com/exploits/1066
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/nntp/ms05_030_nntp.rb

Scores

EPSS 0.8257
EPSS Percentile 99.2%

Details

Status published
Products (2)
microsoft/outlook_express 5.5 sp2
microsoft/outlook_express 6.0 (2 CPE variants)
Published Jun 14, 2005
Tracked Since Feb 18, 2026