Windows Mail
Vendor:
First CVE: Jun 12, 2007 · Active for 19 years
6
Total CVEs
More Total CVEs than 80% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Windows Mail over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 12, 2007
19 years ago
Most Recent CVE
Jul 11, 2018
2,935 days ago
CVE Severity & Scoring
Windows Mail6 CVEs
50%
50%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (16.7%)
Unknown5 (83.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (16.7%)
High0 (0.0%)
Unknown5 (83.3%)
User Interaction
None0 (0.0%)
Unknown5 (83.3%)
Required1 (16.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (16.7%)
Unknown5 (83.3%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3897HIGH Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary | Oct 9, 2007 | 9.3 | 54 | NO | NO |
CVE-2010-0816HIGH Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gol | May 12, 2010 | 9.3 | 50 | NO | YES |
CVE-2008-1448HIGH The MHTML protocol handler in a component of Microsoft Outlook Express 5.5 SP2 and 6 through SP1, and Windows Mail, does not assign the correct Internet Explorer Security Zone to U | Aug 13, 2008 | 7.1 | 30 | NO | NO |
CVE-2018-8305MEDIUM An information disclosure vulnerability exists in Windows Mail Client when a message is opened, aka "Windows Mail Client Information Disclosure Vulnerability." This affects Mail, C | Jul 11, 2018 | 6.5 | 24 | NO | NO |
CVE-2007-2225MEDIUM A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote | Jun 12, 2007 | 4.3 | 24 | NO | NO |
CVE-2007-2227MEDIUM The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attack | Jun 12, 2007 | 4.3 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Windows Mail
Top CWEs
Versions
No cataloged versions.