CVE-2006-3778
IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the (1) "Save As Draft" option is used or (2) a "," (comma) is inside the "phrase" portion of an address, which can cause the e-mail to be sent to users that were deleted from the To, CC, and BCC fields, which allows remote attackers to obtain the list of original recipients.
- Affected products
- Ibm Lotus Notes
- Ibm Lotus Notes
- = 6.0, 6.5, 7.0
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 1.5% (71th percentile)
- NVD status
- Modified
- Published
- 2006-07-21
CVE-2006-3778 at NVD
No indexed exploits for CVE-2006-3778 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2006-3778 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.