← All CVEs

CVE-2002-1604

high · 7.5

Multiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbitrary code via a long NLSPATH environment variable to (1) csh, (2) dtsession, (3) dxsysinfo, (4) imapd, (5) inc, (6) uucp, (7) uux, (8) rdist, or (9) deliver.

7.5
CVSS
15.0%
EPSS (exploit prob.)
97th
EPSS percentile
2002-09-02
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
hphp-ux10.20
hphp-ux11.00
hphp-ux11.04
hphp-ux11.11
hphp-ux11.22
hptru644.0f
hptru644.0g
hptru645.0a
hptru645.1
hptru645.1a

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-1604