← Back

CVE-2010-0816

nvd nist
Published: May 12, 2010Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote e-mail servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) POP3 or (2) IMAP response, as demonstrated by a certain +OK response on TCP port 110, aka "Outlook Express and Windows Mail Integer Overflow Vulnerability."

Affected (5)

3 products
Outlook Express
Windows Live Mail
Windows Mail
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Microsoft
Version 5.5 sp2
Version 6.0 sp1
Running on/withPlatform Versions
Microsoft
Windows 2000
All versions
Configuration B
2 platform
Running on/withPlatform Versions
Microsoft
Windows Xp
All versions
Microsoft
Windows Xp
All versions
Configuration C
1 platform
Running on/withPlatform Versions
Microsoft
Windows Xp
All versions
Configuration D
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Version 6.0
Running on/withPlatform Versions
Microsoft
Windows 2003 Server
All versions
Microsoft
Windows 2003 Server
All versions
Microsoft
Windows Server 2003
All versions
Configuration E
14 platform
Running on/withPlatform Versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Vista
All versions
Microsoft
Windows Vista
All versions
Microsoft
Windows Vista
All versions
Microsoft
Windows Vista
All versions
Configuration F
2 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
All versions
All versions
Running on/withPlatform Versions
Microsoft
Windows 7
All versions
Microsoft
Windows Server 2008
Version r2
Microsoft
Windows Server 2008
Version r2

Related CWEs

Timeline

No history available yet.