← All CVEs

CVE-2002-0228

medium · 5

Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites).

5
CVSS
19.9%
EPSS (exploit prob.)
97th
EPSS percentile
2002-05-16
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

VendorProductAffected versions
microsoftmsn_messenger2.2
microsoftmsn_messenger3.0
microsoftmsn_messenger4.0
microsoftmsn_messenger4.5
microsoftmsn_messenger4.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-0228