Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2002-0391

Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.

  • Published: Aug 12, 2002
  • Updated: May 9, 2024
  • CVE: CVE-2002-0391
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 10
  • AV:N/AC:L/Au:N/C:C/I:C/A:C

CWEs:

Software From Fixed in
freebsd / freebsd - 4.6.1.x
openbsd / openbsd 3.1 3.1.x
sun / sunos 5.7 5.7.x
sun / sunos 5.8 5.8.x
sun / solaris 9.0 9.0.x
sun / sunos 5.5.1 5.5.1.x
sun / solaris 2.6 2.6.x
microsoft / windows_nt 4.0 4.0.x