VDB
CVE-2001-0660
CVE-2001-0660
PUBLISHED
CVSS 5 MEDIUM
Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresses by directly accessing a back-end function that processes the global address list (GAL).
EPSS 19.55% · 95.5th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
19.55%
95.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| microsoft | exchange_server | 0 |
Timeline
- Oct 30, 2001 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- MS01-047 vendor-advisory
- 3301 vdb
- Q307195 vendor-advisory
- exchange-owa-obtain-addresses(7089) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2001-0660 advisory