{"api_version":"1","generated_at":"2026-07-23T02:35:57+00:00","cve":"CVE-2004-2137","urls":{"html":"https://cve.report/CVE-2004-2137","api":"https://cve.report/api/cve/CVE-2004-2137.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2137","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2137"},"summary":{"title":"CVE-2004-2137","description":"Outlook Express 6.0, when sending multipart e-mail messages using the \"Break apart messages larger than\" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://support.microsoft.com/kb/843555","name":"http://support.microsoft.com/kb/843555","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"E-mail recipients who are listed in the BCC box can be viewed by e-mail recipients who are listed in the To and CC boxes when you send a multi-part e-mail message by using Outlook Express 6.0","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/12376","name":"http://secunia.com/advisories/12376","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - Microsoft Outlook Express \"BCC:\" Recipient Disclosure Weakness","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.networksecurity.fi/advisories/outlook-bcc.html","name":"http://www.networksecurity.fi/advisories/outlook-bcc.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"This domain name is registered with Netim","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1011067","name":"http://securitytracker.com/id?1011067","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"SecurityTracker.com Archives - Microsoft Outlook Express May Disclose 'bcc:' Recipient Addresses","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/9167","name":"http://www.osvdb.org/9167","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17098","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17098","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/11040","name":"http://www.securityfocus.com/bid/11040","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Outlook Express BCC Field Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2137","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2137","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2137","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"outlook_express","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2137","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"outlook_express","cpe6":"6.0","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:15:01.602Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"11040","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11040"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.networksecurity.fi/advisories/outlook-bcc.html"},{"name":"1011067","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1011067"},{"name":"outlook-email-address-disclosure(17098)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17098"},{"name":"843555","tags":["vendor-advisory","x_refsource_MSKB","x_transferred"],"url":"http://support.microsoft.com/kb/843555"},{"name":"12376","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/12376"},{"name":"9167","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/9167"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-08-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"Outlook Express 6.0, when sending multipart e-mail messages using the \"Break apart messages larger than\" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"11040","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11040"},{"tags":["x_refsource_MISC"],"url":"http://www.networksecurity.fi/advisories/outlook-bcc.html"},{"name":"1011067","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1011067"},{"name":"outlook-email-address-disclosure(17098)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17098"},{"name":"843555","tags":["vendor-advisory","x_refsource_MSKB"],"url":"http://support.microsoft.com/kb/843555"},{"name":"12376","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/12376"},{"name":"9167","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/9167"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2137","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Outlook Express 6.0, when sending multipart e-mail messages using the \"Break apart messages larger than\" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"11040","refsource":"BID","url":"http://www.securityfocus.com/bid/11040"},{"name":"http://www.networksecurity.fi/advisories/outlook-bcc.html","refsource":"MISC","url":"http://www.networksecurity.fi/advisories/outlook-bcc.html"},{"name":"1011067","refsource":"SECTRACK","url":"http://securitytracker.com/id?1011067"},{"name":"outlook-email-address-disclosure(17098)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/17098"},{"name":"843555","refsource":"MSKB","url":"http://support.microsoft.com/kb/843555"},{"name":"12376","refsource":"SECUNIA","url":"http://secunia.com/advisories/12376"},{"name":"9167","refsource":"OSVDB","url":"http://www.osvdb.org/9167"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2137","datePublished":"2005-06-14T04:00:00.000Z","dateReserved":"2005-06-14T00:00:00.000Z","dateUpdated":"2024-08-08T01:15:01.602Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:outlook_express:6.0:*:*:*:*:*:*:*","matchCriteriaId":"85FD3557-956D-4A96-8AA5-5FD9DB87FD11"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:outlook_express:6.0:sp1:*:*:*:*:*:*","matchCriteriaId":"D45F2775-A10B-4834-A2EF-7498EEAB155D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2137","Ordinal":"1","Title":"CVE-2004-2137","CVE":"CVE-2004-2137","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2137","Ordinal":"1","NoteData":"Outlook Express 6.0, when sending multipart e-mail messages using the \"Break apart messages larger than\" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information.","Type":"Description","Title":"CVE-2004-2137"},{"CveYear":"2004","CveId":"2137","Ordinal":"2","NoteData":"2005-06-14","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"2137","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}