VulnerabilityModified
CVE-2005-2858
The Fetch.FetchContact.1 ActiveX control (Fetch.dll) for Rediff Bol 7.0 allows remote attackers to read the Windows Address Book via the FullAddressBook method.
MEDIUM 5.0EPSS 1.31%
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
The Fetch.FetchContact.1 ActiveX control (Fetch.dll) for Rediff Bol 7.0 allows remote attackers to read the Windows Address Book via the FullAddressBook method.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/16685Vendor Advisory
- http://www.infogreg.com/security/im/rediff-bol-7-exposes-wab.htmlExploit, Vendor Advisory, URL Repurposed
- http://secunia.com/advisories/16685Vendor Advisory
- http://www.infogreg.com/security/im/rediff-bol-7-exposes-wab.htmlExploit, Vendor Advisory, URL Repurposed
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.