VDB
CVE-2002-0370
CVE-2002-0370
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.
EPSS 30.16% · 96.8th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
30.16%
96.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| verity | keyview_viewing_sdk | gold |
| ibm | lotus_notes | 5.0.1, 5.0.2, 5.0.3 |
| microsoft | windows_98_plus_pack | |
| allume_systems_division | stuffit_expander | 6.5.2 |
| microsoft | windows_me | |
| microsoft | windows_xp | |
| winzip | winzip | 7.0 |
Timeline
- Oct 5, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- http://www.info.apple.com/usen/security/security_updates.html url
- http://www.info-zip.org/FAQ.html url
- win-zip-decompression-bo(10251) vdb
- 20021002 R7-0004: Multiple Vendor Long ZIP Entry Filename Processing Issues mailing-list
- 587 third-party-advisory
- 20021002 R7-0004: Multiple Vendor Long ZIP Entry Filename Processing Issues mailing-list
- VU#383779 third-party-advisory
- MS02-054 vendor-advisory
- 5873 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2002-0370 advisory