VDB
CVE-2002-1306
CVE-2002-1306
PUBLISHED
CVSS 7.5 HIGH
Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote attackers to execute arbitrary code via a certain "lan://" URL.
EPSS 5.80% · 92.4th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
5.80%
92.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| kde | kde | 2.1.2, 2.1, 2.1.1 |
| n/a | n/a | n/a |
Timeline
- Nov 21, 2002 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 20021112 KDE Security Advisory: resLISa / LISa Vulnerabilities mailing-list
- SuSE-SA:2002:042 vendor-advisory
- http://www.kde.org/info/security/advisory-20021111-2.txt url
- kde-kdenetwork-lisa-bo(10597) vdb
- kde-kdenetwork-lan-bo(10598) vdb
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-080.php technical
- http://www.redhat.com/support/errata/RHSA-2002-220.html technical
- https://nvd.nist.gov/vuln/detail/CVE-2002-1306 advisory
- http://marc.info/?l=bugtraq&m=103728981029342&w=2 url
- http://www.ciac.org/ciac/bulletins/n-020.shtml url
- http://www.debian.org/security/2002/dsa-214 url