CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:C/I:N/A:N
AI Score
Confidence
Low
EPSS
Percentile
66.3%
Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated by reading PalmDatabase.db3.
Vendor | Product | Version | CPE |
---|---|---|---|
hp | palm_pre_webos | * | cpe:2.3:o:hp:palm_pre_webos:*:*:*:*:*:*:*:* |
hp | palm_pre_webos | 1.0.2 | cpe:2.3:o:hp:palm_pre_webos:1.0.2:*:*:*:*:*:*:* |
hp | palm_pre_webos | 1.0.3 | cpe:2.3:o:hp:palm_pre_webos:1.0.3:*:*:*:*:*:*:* |
hp | palm_pre_webos | 1.0.4 | cpe:2.3:o:hp:palm_pre_webos:1.0.4:*:*:*:*:*:*:* |