VDB
CVE-2002-0655
CVE-2002-0655
PUBLISHED
CVSS 7.5 HIGH
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.
EPSS 0.88% · 75.8th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
0.88%
75.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | mac_os_x | 10.1.4, 10.1.5, 10.1.1 |
| n/a | n/a | * |
| oracle | http_server | 9.0.1, 9.2.0 |
| openssl | openssl | 0.9.1c, 0.9.2b, 0.9.3 |
| oracle | corporate_time_outlook_connector | 3.1, 3.3, 3.1.2 |
| oracle | application_server | 1.0.2.1s, 1.0.2, 1.0.2.2 |
Timeline
- Jul 31, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 3, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- May 29, 2023 EPSS Score
References
- 5364 vdb
- VU#308891 third-party-advisory
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-033.1.txt technical
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000513 technical
- http://www.cert.org/advisories/CA-2002-23.html advisory
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-033.0.txt technical
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:33.openssl.asc technical
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-046.php technical
- https://nvd.nist.gov/vuln/detail/CVE-2002-0655 advisory