VulnerabilityModified
CVE-2007-5493
The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded.
MEDIUM 4.3EPSS 4.18%
Does this matter?
Lower severity and a low EPSS score (4.18%). Track it; it rarely justifies an emergency change on its own.
Description
The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 4.18% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- microsoft/windows mobile
- Source
- cve@mitre.org
References
- http://osvdb.org/45517
- http://securitytracker.com/id?1018832
- http://www.securityfocus.com/archive/1/482446/100/0/threaded
- http://www.securityfocus.com/bid/26091
- http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-011.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37249
- http://osvdb.org/45517
- http://securitytracker.com/id?1018832
- http://www.securityfocus.com/archive/1/482446/100/0/threaded
- http://www.securityfocus.com/bid/26091
- http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-011.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37249
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.