VDB
CVE-2002-1306
CVE-2002-1306
PUBLISHED
CVSS 7.5 HIGH
Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote attackers to execute arbitrary code via a certain "lan://" URL.
EPSS 5.54% · 90.4th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
5.54%
90.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| kde | kde | 2.1.2, 2.1, 2.1.1 |
| n/a | n/a | n/a |
Exploit Intelligence
- MDKSA-2002:080 (circl)
- 20021114 GLSA: kdelibs (circl)
- 20021112 KDE Security Advisory: resLISa / LISa Vulnerabilities (circl)
- http://www.kde.org/info/security/advisory-20021111-2.txt (circl)
- kde-kdenetwork-lisa-bo(10597) (circl)
- N-020 (circl)
- kde-kdenetwork-lan-bo(10598) (circl)
- DSA-214 (circl)
- RHSA-2002:220 (circl)
- SuSE-SA:2002:042 (circl)
Timeline
- Nov 21, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- MDKSA-2002:080 vendor-advisory
- 20021114 GLSA: kdelibs mailing-list
- 20021112 KDE Security Advisory: resLISa / LISa Vulnerabilities mailing-list
- http://www.kde.org/info/security/advisory-20021111-2.txt url
- kde-kdenetwork-lisa-bo(10597) vdb
- N-020 third-party-advisory
- kde-kdenetwork-lan-bo(10598) vdb
- DSA-214 vendor-advisory
- RHSA-2002:220 vendor-advisory
- SuSE-SA:2002:042 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2002-1306 advisory