Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2008-3068

CVE-2008-3068, Severity pending severity (CVSS —): 5 tracked apps concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
-
Exploitation
-
Tracked apps
5
Still exposed
0

Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

NVD references 17 distinct products for this CVE : only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗

Vulnerable CPE configurations (16)
Vendor Product Versions
microsoft excel
All platforms (wildcard)
-
microsoft excel
All platforms (wildcard)
-
microsoft excel
All platforms (wildcard)
-
microsoft excel
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft outlook
All platforms (wildcard)
-
microsoft outlook
All platforms (wildcard)
-
microsoft outlook
All platforms (wildcard)
-
microsoft outlook
All platforms (wildcard)
-
microsoft powerpoint
All platforms (wildcard)
-
microsoft powerpoint
All platforms (wildcard)
-
microsoft powerpoint
All platforms (wildcard)
-
microsoft powerpoint
All platforms (wildcard)
-
View on NVD ↗