7.5

CVE-2002-1056

Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Outlook Version 2000
Microsoft ≫ Outlook Version 2002
Microsoft ≫ Word Version 2000
Microsoft ≫ Word Version 2000 Update sr1
Microsoft ≫ Word Version 2000 Update sr1a
Microsoft ≫ Word Version 2002
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 18.54% 0.969
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=101760380418890&w=2
http://online.securityfocus.com/archive/1/265621
http://www.iss.net/security_center/static/8708.php
http://www.securityfocus.com/bid/4397
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-021
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A205
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A429