CVE-2002-0152

UnknownEPSS 17.37%

Last modified

CVE-2002-0152 is a vulnerability of currently unknown severity. Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. EPSS estimates a 17.37% chance of exploitation in the next 30 days.

Description

Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.

Metrics

EPSS Probability
17.37%

96.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
MicrosoftEntourage2001
MicrosoftEntouragev._x
MicrosoftExcel2001
MicrosoftExcelx
MicrosoftIe5.1
MicrosoftOffice2001
MicrosoftOfficev.x
MicrosoftOutlook Express5.0
MicrosoftOutlook Express5.0.1
MicrosoftOutlook Express5.0.2
MicrosoftOutlook Express5.0.3
MicrosoftPowerpoint98
MicrosoftPowerpoint2001
MicrosoftPowerpointv.x

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2002-0152?
Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.
How severe is CVE-2002-0152?
Severity scoring for CVE-2002-0152 is pending analysis. The EPSS model estimates a 17.37% probability of exploitation in the next 30 days.
How do I fix CVE-2002-0152?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2002-0152?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST