Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2002-0694 | First vendor Publication | 2002-10-10 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0694 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:403 | |||
Oval ID: | oval:org.mitre.oval:def:403 | ||
Title: | Code Execution via Compiled HTML Help File | ||
Description: | The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2002-0694 | Version: | 7 |
Platform(s): | Microsoft Windows 2000 | Product(s): | HTML Help Facility |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2005-11-03 | Name : Unchecked Buffer in Windows Help(Q323255) File : nvt/smb_nt_ms02-055.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
867 | Microsoft Windows Compiled HTML Help (.chm) Arbitrary Command Execution |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | HTML Help ActiveX Object Access RuleID : 4149 - Revision : 5 - Type : WEB-CLIENT |
2014-01-10 | Microsoft Windows HTML Help hhctrl.ocx clsid access attempt RuleID : 3148-community - Revision : 21 - Type : OS-WINDOWS |
2014-01-10 | Microsoft Windows HTML Help hhctrl.ocx clsid access attempt RuleID : 3148 - Revision : 21 - Type : OS-WINDOWS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2002-10-24 | Name : Arbitrary code can be executed on the remote host through the web client. File : smb_nt_ms02-055.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:46 |
|
2024-11-28 12:05:05 |
|
2024-08-02 12:02:13 |
|
2024-08-02 01:01:20 |
|
2024-02-02 01:02:01 |
|
2024-02-01 12:01:21 |
|
2023-09-05 12:01:55 |
|
2023-09-05 01:01:12 |
|
2023-09-02 12:01:56 |
|
2023-09-02 01:01:13 |
|
2023-08-12 12:02:18 |
|
2023-08-12 01:01:13 |
|
2023-08-11 12:02:00 |
|
2023-08-11 01:01:14 |
|
2023-08-06 12:01:51 |
|
2023-08-06 01:01:14 |
|
2023-08-04 12:01:55 |
|
2023-08-04 01:01:13 |
|
2023-07-14 12:01:53 |
|
2023-07-14 01:01:14 |
|
2023-03-29 01:01:52 |
|
2023-03-28 12:01:19 |
|
2022-10-11 12:01:41 |
|
2022-10-11 01:01:06 |
|
2021-05-04 12:01:42 |
|
2021-04-22 01:01:50 |
|
2020-05-23 00:15:00 |
|
2019-05-09 12:01:12 |
|
2019-04-30 21:19:17 |
|
2018-10-13 00:22:25 |
|
2017-10-10 09:23:24 |
|
2016-08-31 12:00:41 |
|
2016-06-28 14:59:12 |
|
2016-04-26 12:11:35 |
|
2014-02-17 10:24:48 |
|
2013-05-11 12:10:15 |
|