{"api_version":"1","generated_at":"2026-07-23T19:40:09+00:00","cve":"CVE-2002-0228","urls":{"html":"https://cve.report/CVE-2002-0228","api":"https://cve.report/api/cve/CVE-2002-0228.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0228","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0228"},"summary":{"title":"CVE-2002-0228","description":"Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites).","state":"PUBLISHED","assigner":"mitre","published_at":"2002-05-16 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/4028","name":"http://www.securityfocus.com/bid/4028","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft MSN ActiveX Object Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://online.securityfocus.com/archive/1/254021","name":"http://online.securityfocus.com/archive/1/254021","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SecurityFocus HOME Mailing List: BugTraq","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/8084.php","name":"http://www.iss.net/security_center/static/8084.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ISS X-Force Database: msn-messenger-reveal-information (8084): MSN Messenger could reveal sensitive user information","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0228","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0228","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"228","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"msn_messenger","cpe6":"2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"228","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"msn_messenger","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"228","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"msn_messenger","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"228","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"msn_messenger","cpe6":"4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"228","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"msn_messenger","cpe6":"4.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:42:28.577Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20020202 MSN Messenger reveals your name to websites (and can reveal email addresses too)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://online.securityfocus.com/archive/1/254021"},{"name":"msn-messenger-reveal-information(8084)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/8084.php"},{"name":"4028","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4028"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-02-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-05-09T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20020202 MSN Messenger reveals your name to websites (and can reveal email addresses too)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://online.securityfocus.com/archive/1/254021"},{"name":"msn-messenger-reveal-information(8084)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/8084.php"},{"name":"4028","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4028"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0228","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20020202 MSN Messenger reveals your name to websites (and can reveal email addresses too)","refsource":"BUGTRAQ","url":"http://online.securityfocus.com/archive/1/254021"},{"name":"msn-messenger-reveal-information(8084)","refsource":"XF","url":"http://www.iss.net/security_center/static/8084.php"},{"name":"4028","refsource":"BID","url":"http://www.securityfocus.com/bid/4028"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0228","datePublished":"2002-05-03T04:00:00.000Z","dateReserved":"2002-05-01T00:00:00.000Z","dateUpdated":"2024-08-08T02:42:28.577Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-05-16 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:msn_messenger:2.2:*:*:*:*:*:*:*","matchCriteriaId":"0ECE590D-A8FD-4D5F-A082-EA1393BCB72D"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:msn_messenger:3.0:*:*:*:*:*:*:*","matchCriteriaId":"A6DD36B3-F635-4FB9-856B-215D7FE82AF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:msn_messenger:4.0:*:*:*:*:*:*:*","matchCriteriaId":"71BA7CF9-3089-4525-A251-12233978E258"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:msn_messenger:4.5:*:*:*:*:*:*:*","matchCriteriaId":"DFEE276F-4ACC-440B-9F36-FAA7DAD4BAB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:msn_messenger:4.6:*:*:*:*:*:*:*","matchCriteriaId":"083C6323-8712-4A42-893D-6A6BE5997689"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"228","Ordinal":"1","Title":"CVE-2002-0228","CVE":"CVE-2002-0228","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"228","Ordinal":"1","NoteData":"Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites).","Type":"Description","Title":"CVE-2002-0228"},{"CveYear":"2002","CveId":"228","Ordinal":"2","NoteData":"2002-05-03","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"228","Ordinal":"3","NoteData":"2002-05-09","Type":"Other","Title":"Modified"}]}}}