Lucene search

K
cve[email protected]CVE-2002-1770
HistoryJun 21, 2005 - 4:00 a.m.

CVE-2002-1770

2005-06-2104:00:00
web.nvd.nist.gov
24
qualcomm
eudora
remote code execution
html email
cve-2002-1770
security vulnerability

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.5 High

AI Score

Confidence

High

0.017 Low

EPSS

Percentile

87.9%

Qualcomm Eudora 5.1 allows remote attackers to execute arbitrary code via an HTML e-mail message that uses a file:// URL in a t:video tag to reference an attached Windows Media Player file containing JavaScript code, which is launched and executed in the My Computer zone by Internet Explorer.

Affected configurations

NVD
Node
qualcommeudoraMatch5.1
CPENameOperatorVersion
qualcomm:eudoraqualcomm eudoraeq5.1

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.5 High

AI Score

Confidence

High

0.017 Low

EPSS

Percentile

87.9%

Related for CVE-2002-1770