← All CVEs

CVE-2002-0370

high · 7.5

Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.

7.5
CVSS
43.3%
EPSS (exploit prob.)
99th
EPSS percentile
2002-10-10
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
allume_systems_divisionstuffit_expander6.5.2
ibmlotus_notes<= 4.5
ibmlotus_notes5.0
ibmlotus_notes5.0.1
ibmlotus_notes5.0.2
ibmlotus_notes5.0.3
ibmlotus_notes5.0.4
ibmlotus_notes5.0.5
ibmlotus_notes5.0.9a
ibmlotus_notes5.0.10
ibmlotus_notes5.0.11
ibmlotus_notesr5
ibmlotus_notesr6
veritykeyview_viewing_sdkgold
winzipwinzip7.0
microsoftwindows_98_plus_packall versions
microsoftwindows_meall versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-0370