Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2003-1017


Macromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web browsers such as Internet Explorer and Opera, which allows remote attackers to read restricted files via vulnerabilities in web browsers whose exploits rely on predictable names.


Published

2004-01-05T05:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application macromedia director 5.0 Yes
Application macromedia flash_player 4.0_r12 Yes
Application macromedia flash_player 5.0 Yes
Application macromedia flash_player 5.0_r50 Yes
Application macromedia flash_player 6.0 Yes
Application macromedia flash_player 6.0.29.0 Yes
Application macromedia flash_player 6.0.40.0 Yes
Application macromedia flash_player 6.0.47.0 Yes
Application macromedia flash_player 6.0.65.0 Yes
Application macromedia flash_player 6.0.79.0 Yes

References