VulnerabilityModified
CVE-2004-1511
Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certain link sent in a chat window.
MEDIUM 5.0EPSS 2.32%
Does this matter?
Lower severity and a low EPSS score (2.32%). Track it; it rarely justifies an emergency change on its own.
Description
Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certain link sent in a chat window.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.32% probability · 82th percentile
- CISA KEV
- Not listed
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=110014517703092&w=2
- http://secunia.com/advisories/13173Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18038
- http://marc.info/?l=bugtraq&m=110014517703092&w=2
- http://secunia.com/advisories/13173Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18038
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.