7.5

CVE-2001-0398

Exploit
The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT!  to misrepresent the attachment's type with a different icon.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ritlabs ≫ The Bat Version 1.0_build1336
Ritlabs ≫ The Bat Version 1.0_build1349
Ritlabs ≫ The Bat Version 1.1
Ritlabs ≫ The Bat Version 1.011
Ritlabs ≫ The Bat Version 1.14
Ritlabs ≫ The Bat Version 1.15
Ritlabs ≫ The Bat Version 1.015
Ritlabs ≫ The Bat Version 1.17
Ritlabs ≫ The Bat Version 1.18
Ritlabs ≫ The Bat Version 1.19
Ritlabs ≫ The Bat Version 1.21
Ritlabs ≫ The Bat Version 1.22
Ritlabs ≫ The Bat Version 1.028
Ritlabs ≫ The Bat Version 1.029
Ritlabs ≫ The Bat Version 1.31
Ritlabs ≫ The Bat Version 1.031
Ritlabs ≫ The Bat Version 1.32
Ritlabs ≫ The Bat Version 1.032
Ritlabs ≫ The Bat Version 1.33
Ritlabs ≫ The Bat Version 1.34
Ritlabs ≫ The Bat Version 1.035
Ritlabs ≫ The Bat Version 1.35
Ritlabs ≫ The Bat Version 1.036
Ritlabs ≫ The Bat Version 1.36
Ritlabs ≫ The Bat Version 1.037
Ritlabs ≫ The Bat Version 1.39
Ritlabs ≫ The Bat Version 1.039
Ritlabs ≫ The Bat Version 1.041
Ritlabs ≫ The Bat Version 1.41
Ritlabs ≫ The Bat Version 1.42
Ritlabs ≫ The Bat Version 1.42f
Ritlabs ≫ The Bat Version 1.043
Ritlabs ≫ The Bat Version 1.43
Ritlabs ≫ The Bat Version 1.44
Ritlabs ≫ The Bat Version 1.45
Ritlabs ≫ The Bat Version 1.46
Ritlabs ≫ The Bat Version 1.47
Ritlabs ≫ The Bat Version 1.48
Ritlabs ≫ The Bat Version 1.49
Ritlabs ≫ The Bat Version 1.101
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.04% 0.786
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2001-04/0013.html
Vendor Advisory
http://www.securityfocus.com/bid/2530
Patch
Vendor Advisory
Exploit