{"api_version":"1","generated_at":"2026-07-23T00:59:11+00:00","cve":"CVE-2004-0502","urls":{"html":"https://cve.report/CVE-2004-0502","api":"https://cve.report/api/cve/CVE-2004-0502.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-0502","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-0502"},"summary":{"title":"CVE-2004-0502","description":"Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the \"src\" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-08-18 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/11572","name":"http://secunia.com/advisories/11572","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Microsoft Outlook Predictable File Location Weakness","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/10307","name":"http://www.securityfocus.com/bid/10307","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"Microsoft Outlook 2003 Predictable File Location Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=108420583612655&w=2","name":"http://marc.info/?l=bugtraq&m=108420583612655&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'OUTLOOK 2003: OuchLook' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://marc.info/?l=ntbugtraq&m=108644231209698&w=2","name":"http://marc.info/?l=ntbugtraq&m=108644231209698&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Re: PING: Outlook 2003 Spam' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16104","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16104","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=108637351805607&w=2","name":"http://marc.info/?l=bugtraq&m=108637351805607&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'RE: PING: Outlook 2003 Spam' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-0502","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-0502","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"502","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"outlook","cpe6":"2003","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:17:15.093Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"11572","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/11572"},{"name":"20040604 RE: PING: Outlook 2003 Spam","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=108637351805607&w=2"},{"name":"20040509 OUTLOOK 2003: OuchLook","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=108420583612655&w=2"},{"name":"20040604 RE: PING: Outlook 2003 Spam","tags":["mailing-list","x_refsource_NTBUGTRAQ","x_transferred"],"url":"http://marc.info/?l=ntbugtraq&m=108644231209698&w=2"},{"name":"10307","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/10307"},{"name":"outlook-file-location-predictable(16104)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16104"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-05-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the \"src\" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"11572","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/11572"},{"name":"20040604 RE: PING: Outlook 2003 Spam","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=108637351805607&w=2"},{"name":"20040509 OUTLOOK 2003: OuchLook","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=108420583612655&w=2"},{"name":"20040604 RE: PING: Outlook 2003 Spam","tags":["mailing-list","x_refsource_NTBUGTRAQ"],"url":"http://marc.info/?l=ntbugtraq&m=108644231209698&w=2"},{"name":"10307","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/10307"},{"name":"outlook-file-location-predictable(16104)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16104"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-0502","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the \"src\" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"11572","refsource":"SECUNIA","url":"http://secunia.com/advisories/11572"},{"name":"20040604 RE: PING: Outlook 2003 Spam","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=108637351805607&w=2"},{"name":"20040509 OUTLOOK 2003: OuchLook","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=108420583612655&w=2"},{"name":"20040604 RE: PING: Outlook 2003 Spam","refsource":"NTBUGTRAQ","url":"http://marc.info/?l=ntbugtraq&m=108644231209698&w=2"},{"name":"10307","refsource":"BID","url":"http://www.securityfocus.com/bid/10307"},{"name":"outlook-file-location-predictable(16104)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16104"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-0502","datePublished":"2004-06-03T04:00:00.000Z","dateReserved":"2004-05-27T00:00:00.000Z","dateUpdated":"2024-08-08T00:17:15.093Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-08-18 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:outlook:2003:*:*:*:*:*:*:*","matchCriteriaId":"C3189982-F780-4AC2-9663-E6D4DF9DD319"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"502","Ordinal":"1","Title":"CVE-2004-0502","CVE":"CVE-2004-0502","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"502","Ordinal":"1","NoteData":"Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the \"src\" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI.","Type":"Description","Title":"CVE-2004-0502"},{"CveYear":"2004","CveId":"502","Ordinal":"2","NoteData":"2004-06-03","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"502","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}