CVE detail
CVE-2004-2694 — CVE-2004-2694
Published 2004-12-31 · Modified 2026-06-16 · Vendor microsoft · Product outlook_express · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0856
EPSS probability
exploitation probability, 30d
95.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE HREF" with the target set to "_top".
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References