Lucene search

K
cveMitreCVE-2002-0228
HistoryMay 16, 2002 - 4:00 a.m.

CVE-2002-0228

2002-05-1604:00:00
mitre
web.nvd.nist.gov
26
microsoft
msn messenger
javascript
activex
sensitive info
remote attack
cve-2002-0228

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.008

Percentile

82.2%

Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites).

Affected configurations

Nvd
Node
microsoftmsn_messengerMatch2.2
OR
microsoftmsn_messengerMatch3.0
OR
microsoftmsn_messengerMatch4.0
OR
microsoftmsn_messengerMatch4.5
OR
microsoftmsn_messengerMatch4.6
VendorProductVersionCPE
microsoftmsn_messenger2.2cpe:2.3:a:microsoft:msn_messenger:2.2:*:*:*:*:*:*:*
microsoftmsn_messenger3.0cpe:2.3:a:microsoft:msn_messenger:3.0:*:*:*:*:*:*:*
microsoftmsn_messenger4.0cpe:2.3:a:microsoft:msn_messenger:4.0:*:*:*:*:*:*:*
microsoftmsn_messenger4.5cpe:2.3:a:microsoft:msn_messenger:4.5:*:*:*:*:*:*:*
microsoftmsn_messenger4.6cpe:2.3:a:microsoft:msn_messenger:4.6:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.008

Percentile

82.2%

Related for CVE-2002-0228