5
CVSSv2

CVE-2002-1831

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Microsoft MSN Messenger Service 1.0 up to and including 4.6 allows remote malicious users to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft msn messenger 2.0

microsoft msn messenger 3.0

microsoft msn messenger 3.6

microsoft msn messenger 4.0

microsoft msn messenger 4.5

microsoft msn messenger 4.6

microsoft msn messenger 1.0

microsoft msn messenger 2.2

Exploits

source: wwwsecurityfocuscom/bid/4827/info Microsoft's MSN Messenger is an instant messenging client for Windows based machines, based on the Passport system A vulnerability has been reported in some versions of MSN Messenger Under some circumstances, it may be possible to crash the client when it receives a malformed invite request By ...