Vulnerability Name: | CVE-2002-0481 (CCN-8604) | ||||||||
Assigned: | 2002-03-21 | ||||||||
Published: | 2002-03-21 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that references .WMS (Windows Media Skin) or other WMP media files, whose onload handlers execute the player.LaunchURL() Javascript function. | ||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Mar 21 2002 - 13:47:56 CST How Outlook 2002 can still execute JavaScript in an HTML email message Source: MITRE Type: CNA CVE-2002-0481 Source: BUGTRAQ Type: Vendor Advisory 20020321 How Outlook 2002 can still execute JavaScript in an HTML email message Source: XF Type: Vendor Advisory outlook-iframe-javascript(8604) Source: CCN Type: OSVDB ID: 11420 Microsoft Outlook WMP .wms File IFRAME Command Execution Source: BID Type: Patch, Vendor Advisory 4340 Source: CCN Type: BID-4340 Microsoft Outlook IFrame Embedded Media Player File Vulnerability Source: XF Type: UNKNOWN outlook-iframe-javascript(8604) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |