Back
CVE-2003-1378
Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.
Published: Dec 31, 2003
Modified: Jun 16, 2026
CWE-264
CVSS Metrics
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| microsoft | outlook | 2000 |
| microsoft | outlook | 2000 |
| microsoft | outlook | 2000 |
| microsoft | outlook_express | 6.0 |
GitHub Security Advisory GHSA-rx6q-7jmv-mc9j
Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone,...
References (8)
- http://www.securityfocus.com/archive/1/312910 Exploit
- http://www.securityfocus.com/archive/1/312929
- http://www.securityfocus.com/bid/6923 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11411
- http://www.securityfocus.com/archive/1/312910 Exploit
- http://www.securityfocus.com/archive/1/312929
- http://www.securityfocus.com/bid/6923 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11411
Risk Scores
CVSS Score
8.8 / 10
EPSS Score
15.58%
Top 3% most likely to be exploited
Threat Score
39.9 / 100
Data Sources
NVD
EPSS
GitHub