7.5
CVE-2002-0364
- EPSS 31.01%
- Veröffentlicht 03.07.2002 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:57:17
- Erkennungen
Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Information Server Version 4.0
Microsoft ≫ Internet Information Services Version 5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 31.01% | 0.981 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html
http://marc.info/?l=bugtraq&m=102392069305962&w=2
http://marc.info/?l=ntbugtraq&m=102392308608100&w=2
http://online.securityfocus.com/archive/1/276767
http://www.iss.net/security_center/static/9327.php
http://www.kb.cert.org/vuls/id/313819
http://www.securityfocus.com/bid/4855
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-028
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A182
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A29