SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2001-0642

Directory traversal vulnerability in IncrediMail version 1400185 and earlier allows local users to overwrite files on the local hard drive by appending ..

LOW 2.1EPSS 0.49%

Does this matter?

Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.

Description

Directory traversal vulnerability in IncrediMail version 1400185 and earlier allows local users to overwrite files on the local hard drive by appending .. (dot dot) sequences to filenames listed in the content.ini file.

CVSS 2.0
2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
EPSS
0.49% probability · 41th percentile
CISA KEV
Not listed
Affected
incredimail/incredimail
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.