CVE-2004-0502
Estado: ModificadaMedia (5)—💥 Exploit
Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 20%
- Percentil entre todas las CVEs puntuadas: 97
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · Microsoft Outlook 2003 - Predictable File Location (10/5/2004)
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://marc.info/?l=bugtraq&m=108420583612655&w=2
- http://marc.info/?l=bugtraq&m=108637351805607&w=2
- http://marc.info/?l=ntbugtraq&m=108644231209698&w=2
- http://secunia.com/advisories/11572
- http://www.securityfocus.com/bid/10307
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16104
- http://marc.info/?l=bugtraq&m=108420583612655&w=2
- http://marc.info/?l=bugtraq&m=108637351805607&w=2
- http://marc.info/?l=ntbugtraq&m=108644231209698&w=2
- http://secunia.com/advisories/11572
- http://www.securityfocus.com/bid/10307
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16104
JSON original (NVD)
Mostrar
{
"id": "CVE-2004-0502",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2004-08-18T04:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=108420583612655&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=108637351805607&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=ntbugtraq&m=108644231209698&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/11572",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/10307",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16104",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=108420583612655&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=108637351805607&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=ntbugtraq&m=108644231209698&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/11572",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/10307",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16104",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the \"src\" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI."
},
{
"lang": "es",
"value": "Outlook 2003, cuando se responde a un mensaje de correo electrónico, almacena ciertos ficheros en una situación predecible para la fuente de una imagen (etiqueta HTML img) del mensaje original, lo que permite a atacantes remotos saltarse restricciones de zonas y explotar otros cosas que dependen de localizaciones impredecibles, como se ha demostrado usando una URI shell:"
}
],
"lastModified": "2026-06-16T22:05:46.033",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:outlook:2003:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C3189982-F780-4AC2-9663-E6D4DF9DD319"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}