7.5

CVE-2002-0392

Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.

Data is provided by the National Vulnerability Database (NVD)
ApacheHTTP Server Version >= 1.2.2 <= 1.3.24
ApacheHTTP Server Version >= 2.0.0 <= 2.0.36
DebianDebian Linux Version2.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 59.3% 0.982
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
http://online.securityfocus.com/advisories/4240
Third Party Advisory
Broken Link
VDB Entry
http://online.securityfocus.com/advisories/4257
Third Party Advisory
Broken Link
VDB Entry
http://online.securityfocus.com/archive/1/278149
Third Party Advisory
Broken Link
VDB Entry
http://www.cert.org/advisories/CA-2002-17.html
Patch
Third Party Advisory
US Government Resource
http://www.kb.cert.org/vuls/id/944335
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/20005
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/5033
Third Party Advisory
VDB Entry