5.8
CVE-2004-2649
- EPSS 2.53%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:10:03
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as " ") in the middle of the URL.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.53% | 0.828 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://archives.neohapsis.com/archives/bugtraq/2004-05/0066.html
http://secunia.com/advisories/11581
http://securitytracker.com/alerts/2004/May/1010117.html
http://www.eudora.com/download/eudora/windows/6.1.2/RelNotes.txt
http://www.osvdb.org/6009
http://www.securityfocus.com/bid/10305
https://exchange.xforce.ibmcloud.com/vulnerabilities/16105