cbcvebase.
CVE-2004-0122
published 2004-04-15

CVE-2004-0122: Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.

medium5CVSS 3.1
AVNACLAuNCPINAN
Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.

Affected

16 ranges
VendorProductVersion rangeFixed in
adiumadium
debianpidgin< pidgin 2.6.5-1 (bookworm)pidgin 2.6.5-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
microsoftmsn_messenger
microsoftmsn_messenger
opensuseopensuse11.0 – 11.2
pidginpidgin
pidginpidgin>= 0 < 2.6.5-12.6.5-1
pidginpidgin>= 0 < 2.6.5-12.6.5-1
pidginpidgin>= 0 < 2.6.5-12.6.5-1
pidginpidgin>= 0 < 2.6.5-12.6.5-1
redhatenterprise_linux
redhatenterprise_linux
suselinux_enterprise
suselinux_enterprise_server

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd5.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM