VDB

CVE-2002-1121

CVE-2002-1121 PUBLISHED CVSS 7.5 HIGH

SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly") and supported in such products as Outlook Express, which allows remote attackers to bypass content filtering, including virus checking, via fragmented emails of the message/partial content type.

EPSS 0.94% · 76.6th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
0.94%
76.6th percentile

Affected Products

VendorProductVersions
trend_microinterscan_viruswall3.5, 3.52, 3.51
gfimailsecurity7.2
n/an/an/a
roaring_penguincanit1.2
roaring_penguinmimedefang2.14, 2.20
network_associateswebshield_smtp4.5.74.0, 4.5.44, 4.5

Timeline

  • Sep 14, 2002 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Apr 30, 2022 CVE Updated
  • May 20, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›