CVE-2007-2225

Microsoft Outlook Express 6 and Windows Mail - Cross-Domain Information Disclosure via MHTML URL Parsing

Title source: llm
STIX 2.1

Description

A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "URL Parsing Cross Domain Information Disclosure Vulnerability."

References (14)

Core 14
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018232
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/682825
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/471947/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24392
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/472002/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/35345
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018231
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA07-163A.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2045
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25639
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2154

Scores

EPSS 0.2504
EPSS Percentile 97.7%

Details

Status published
Products (2)
microsoft/outlook_express 6.0
microsoft/windows_mail
Published Jun 12, 2007
Tracked Since Feb 18, 2026