CVE-2005-1987

Microsoft Exchange Server - Buffer Overflow

Title source: rule
STIX 2.1

Description

Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.

References (19)

Core 19
Core References
Broken Link vdb-entry x_refsource_osvdb
http://www.osvdb.org/19905
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ907245
Third Party Advisory vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A581
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/883460
Third Party Advisory vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A848
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/22495
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17167
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15067
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-048
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA05-284A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015038
Broken Link mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0289.html
Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112915118302012&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015039

Scores

EPSS 0.5702
EPSS Percentile 98.2%

Details

CWE
CWE-120
Status published
Products (6)
microsoft/exchange_server 2000 sp3
microsoft/windows_2000
microsoft/windows_server_2003 (2 CPE variants)
microsoft/windows_server_2003 r2
microsoft/windows_server_2003 sp1 (2 CPE variants)
microsoft/windows_xp (3 CPE variants)
Published Oct 13, 2005
Tracked Since Feb 18, 2026