CVE-2002-0364
high · 7.5Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."
7.5
CVSS
31.0%
EPSS (exploit prob.)
98th
EPSS percentile
2002-07-03
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | internet_information_server | 4.0 |
| microsoft | internet_information_services | 5.0 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html
- http://marc.info/?l=bugtraq&m=102392069305962&w=2
- http://marc.info/?l=ntbugtraq&m=102392308608100&w=2
- http://online.securityfocus.com/archive/1/276767
- http://www.iss.net/security_center/static/9327.php
- http://www.kb.cert.org/vuls/id/313819
- http://www.securityfocus.com/bid/4855
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-028
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A182
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A29
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html
- http://marc.info/?l=bugtraq&m=102392069305962&w=2
- http://marc.info/?l=ntbugtraq&m=102392308608100&w=2
- http://online.securityfocus.com/archive/1/276767
- http://www.iss.net/security_center/static/9327.php
- http://www.kb.cert.org/vuls/id/313819
- http://www.securityfocus.com/bid/4855
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-028
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A182
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A29
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2002-0364