Lucene search

K
cve[email protected]CVE-2002-0370
HistoryOct 10, 2002 - 4:00 a.m.

CVE-2002-0370

2002-10-1004:00:00
web.nvd.nist.gov
1036
cve-2002-0370
buffer overflow
dos attack
arbitrary code execution
zip files vulnerability.

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.9 High

AI Score

Confidence

High

0.041 Low

EPSS

Percentile

92.2%

Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.

Affected configurations

NVD
Node
allume_systems_divisionstuffit_expanderMatch6.5.2
OR
ibmlotus_notesRange4.5
OR
ibmlotus_notesMatch5.0
OR
ibmlotus_notesMatch5.0.1
OR
ibmlotus_notesMatch5.0.2
OR
ibmlotus_notesMatch5.0.3
OR
ibmlotus_notesMatch5.0.4
OR
ibmlotus_notesMatch5.0.5
OR
ibmlotus_notesMatch5.0.9a
OR
ibmlotus_notesMatch5.0.10
OR
ibmlotus_notesMatch5.0.11
OR
ibmlotus_notesMatchr5
OR
ibmlotus_notesMatchr6
OR
veritykeyview_viewing_sdkMatchgold
OR
winzipwinzipMatch7.0
Node
microsoftwindows_98_plus_pack
OR
microsoftwindows_me
OR
microsoftwindows_xphome
OR
microsoftwindows_xpgoldprofessional
OR
microsoftwindows_xpsp1home

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.9 High

AI Score

Confidence

High

0.041 Low

EPSS

Percentile

92.2%