{"api_version":"1","generated_at":"2026-07-23T06:41:51+00:00","cve":"CVE-2007-5470","urls":{"html":"https://cve.report/CVE-2007-5470","api":"https://cve.report/api/cve/CVE-2007-5470.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5470","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5470"},"summary":{"title":"CVE-2007-5470","description":"Microsoft Expression Media stores the catalog password in cleartext in the catalog IVC file, which allows local users to obtain sensitive information and gain access to the catalog by reading the IVC file.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-10-16 00:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-200","CWE-310","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/25996","name":"http://www.securityfocus.com/bid/25996","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Expression Media Plaintext Password Storage Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/27144","name":"http://secunia.com/advisories/27144","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Microsoft Expression Media Password Disclosure Weakness - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.microsoft.com/kb/942109","name":"http://support.microsoft.com/kb/942109","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"A password is stored in plain text when you add the password to a catalog in Expression Media","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://osvdb.org/38486","name":"http://osvdb.org/38486","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5470","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5470","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5470","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"expression_media","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:31:59.061Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"27144","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27144"},{"name":"942109","tags":["vendor-advisory","x_refsource_MSKB","x_transferred"],"url":"http://support.microsoft.com/kb/942109"},{"name":"25996","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25996"},{"name":"38486","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/38486"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-09-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft Expression Media stores the catalog password in cleartext in the catalog IVC file, which allows local users to obtain sensitive information and gain access to the catalog by reading the IVC file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-11-01T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"27144","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27144"},{"name":"942109","tags":["vendor-advisory","x_refsource_MSKB"],"url":"http://support.microsoft.com/kb/942109"},{"name":"25996","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25996"},{"name":"38486","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/38486"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5470","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft Expression Media stores the catalog password in cleartext in the catalog IVC file, which allows local users to obtain sensitive information and gain access to the catalog by reading the IVC file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"27144","refsource":"SECUNIA","url":"http://secunia.com/advisories/27144"},{"name":"942109","refsource":"MSKB","url":"http://support.microsoft.com/kb/942109"},{"name":"25996","refsource":"BID","url":"http://www.securityfocus.com/bid/25996"},{"name":"38486","refsource":"OSVDB","url":"http://osvdb.org/38486"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5470","datePublished":"2007-10-16T00:00:00.000Z","dateReserved":"2007-10-15T00:00:00.000Z","dateUpdated":"2024-08-07T15:31:59.061Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-10-16 00:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-200","CWE-310","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:expression_media:*:*:*:*:*:*:*:*","matchCriteriaId":"D9EF0FC1-25B7-4909-96DA-69BC897AA29C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5470","Ordinal":"1","Title":"CVE-2007-5470","CVE":"CVE-2007-5470","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5470","Ordinal":"1","NoteData":"Microsoft Expression Media stores the catalog password in cleartext in the catalog IVC file, which allows local users to obtain sensitive information and gain access to the catalog by reading the IVC file.","Type":"Description","Title":"CVE-2007-5470"},{"CveYear":"2007","CveId":"5470","Ordinal":"2","NoteData":"2007-10-15","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5470","Ordinal":"3","NoteData":"2007-11-01","Type":"Other","Title":"Modified"}]}}}