← back
CVE-2002-0392observed exploitation

CVE-2002-0392

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 95%
from disclosure to weapon0 days
Published on NVDApr 2
1st PoCJun 17
metasploitJun 19
VulnCheckJun 17
exploitation probability
95%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
10 products
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 · Red Hat Linux 6.2 · Red Hat Linux 7.0 · Red Hat Linux 7.1 · Red Hat Linux 7.2 · and others 5
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.