Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Sasa Kos

Researcher fromACROS Security
#51798of 56,330
5Total CVSS
Vulnerabilities · 1
PT-2004-1438
5.0
2004-03-18
Microsoft · Outlook · CVE-2004-0284
**Name of the Vulnerable Software and Affected Versions** Microsoft Internet Explorer version 6.0 Microsoft Outlook version 2002 Microsoft Outlook version 2003 **Description** The issue allows remote attackers to cause a denial of service, specifically CPU consumption, under certain conditions. This can be triggered by visiting a web site or opening an HTML e-mail that contains two null characters (%00) after the host name, provided that the "Do not save encrypted pages to disk" option is disabled. **Recommendations** For Microsoft Internet Explorer version 6.0, enable the "Do not save encrypted pages to disk" option to prevent exploitation. For Microsoft Outlook version 2002, enable the "Do not save encrypted pages to disk" option to prevent exploitation. For Microsoft Outlook version 2003, enable the "Do not save encrypted pages to disk" option to prevent exploitation.