CVE Vulnerabilities

CVE-2002-1056

Published: May 16, 2002 | Modified: Oct 12, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.

Affected Software

Name Vendor Start Version End Version
Outlook Microsoft 2000 (including) 2000 (including)
Outlook Microsoft 2002 (including) 2002 (including)
Word Microsoft 2000 (including) 2000 (including)
Word Microsoft 2000-sr1 (including) 2000-sr1 (including)
Word Microsoft 2000-sr1a (including) 2000-sr1a (including)
Word Microsoft 2002 (including) 2002 (including)

References