Lucene search

K
cveMitreCVE-2004-1325
HistoryJan 06, 2005 - 5:00 a.m.

CVE-2004-1325

2005-01-0605:00:00
mitre
web.nvd.nist.gov
28
cve-2004-1325
activex control
windows media player 9.0
file existence
remote attackers
security issue

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.9

Confidence

Low

EPSS

0.653

Percentile

97.9%

The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of the file if the file exists, which allows remote attackers to determine the existence of files on the local system.

Affected configurations

Nvd
Node
microsoftwindows_media_playerMatch9
VendorProductVersionCPE
microsoftwindows_media_player9cpe:2.3:a:microsoft:windows_media_player:9:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.9

Confidence

Low

EPSS

0.653

Percentile

97.9%

Related for CVE-2004-1325