Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Jun 16, 2026
CVE-2004-2137
CVE-2004-2137
Description
Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:microsoft:outlook_express:6.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:outlook_express:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:outlook_express:6.0:sp1:*:*:*:*:*:*
- (no CPE)range: =6.0
Patches
Vulnerability mechanics
References
7- secunia.com/advisories/12376nvdPatchVendor Advisory
- securitytracker.com/idnvdPatch
- support.microsoft.com/kb/843555nvdPatchVendor Advisory
- www.networksecurity.fi/advisories/outlook-bcc.htmlnvdPatchVendor Advisory
- www.osvdb.org/9167nvd
- www.securityfocus.com/bid/11040nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/17098nvd
News mentions
0No linked articles in our index yet.