Back
CVE-2005-1185
Unquoted Windows search path vulnerability in Musicmatch Jukebox 10.00.2047 and earlier allows local users to gain privileges via a malicious C:\program.exe file, which is run by MMFWLaunch.exe when it attempts to execute launch.exe.
Published: May 2, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| musicmatch | jukebox | * |
GitHub Security Advisory GHSA-fjvv-mmvx-rhpg
Unquoted Windows search path vulnerability in Musicmatch Jukebox 10.00.2047 and earlier allows...
References (8)
- http://marc.info/?l=bugtraq&m=111352290711509&w=2
- http://securitytracker.com/id?1013718 Patch
- http://www.hyperdose.com/advisories/H2005-05.txt Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20129
- http://marc.info/?l=bugtraq&m=111352290711509&w=2
- http://securitytracker.com/id?1013718 Patch
- http://www.hyperdose.com/advisories/H2005-05.txt Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20129
Risk Scores
CVSS Score
4.6 / 10
EPSS Score
0.34%
Top 73% most likely to be exploited
Threat Score
18.5 / 100
Data Sources
NVD
EPSS
GitHub