Vulnerability Name:

CVE-2002-1770 (CCN-8609)

Assigned:2002-03-22
Published:2002-03-22
Updated:2017-07-11
Summary:Qualcomm Eudora 5.1 allows remote attackers to execute arbitrary code via an HTML e-mail message that uses a file:// URL in a t:video tag to reference an attached Windows Media Player file containing JavaScript code, which is launched and executed in the My Computer zone by Internet Explorer.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2002-1770

Source: BUGTRAQ
Type: UNKNOWN
2002032 Automatically opening IE + Executing attachments

Source: NTBUGTRAQ
Type: UNKNOWN
2002032 Automatically opening IE + Executing attachments

Source: CCN
Type: GreyMagic Security Advisory GM#002-IE
Automatically opening IE + Executing attachments.

Source: MISC
Type: Exploit, Vendor Advisory
http://security.greymagic.com/adv/gm002-ie/

Source: CCN
Type: OSVDB ID: 59755
Eudora t:video Tag file:// URI Handling Arbitrary Code Execution

Source: BID
Type: UNKNOWN
4343

Source: CCN
Type: BID-4343
Qualcomm Eudora WebBrowser Control Embedded Media Player File Vulnerability

Source: XF
Type: UNKNOWN
msviewer-tvideo-execute-attachment(8609)

Source: XF
Type: UNKNOWN
msviewer-tvideo-execute-attachment(8609)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:qualcomm:eudora:5.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:qualcomm:eudora:*:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:outlook:*:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:outlook_express:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    qualcomm eudora 5.1
    qualcomm eudora *
    microsoft outlook *
    microsoft outlook express *