← All CVEs

CVE-2002-0392

high · 7.5

Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.

7.5
CVSS
95.0%
EPSS (exploit prob.)
100th
EPSS percentile
2002-07-03
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
apachehttp_server>= 1.2.2, <= 1.3.24
apachehttp_server>= 2.0.0, <= 2.0.36
debiandebian_linux2.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-0392