VulnerabilityModified
CVE-2002-0696
Microsoft Visual FoxPro 6.0 does not register its associated files with Internet Explorer, which allows remote attackers to execute Visual FoxPro applications without warning via HTML that references specially-crafted filenames.
HIGH 7.5EPSS 11.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Visual FoxPro 6.0 does not register its associated files with Internet Explorer, which allows remote attackers to execute Visual FoxPro applications without warning via HTML that references specially-crafted filenames.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 11.70% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/visual foxpro
- Source
- cve@mitre.org
References
- http://www.ciac.org/ciac/bulletins/m-120.shtml
- http://www.iss.net/security_center/static/10035.phpVendor Advisory
- http://www.securityfocus.com/bid/5633Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-049
- http://www.ciac.org/ciac/bulletins/m-120.shtml
- http://www.iss.net/security_center/static/10035.phpVendor Advisory
- http://www.securityfocus.com/bid/5633Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-049
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.