// For flags

CVE-2002-0155

 

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Buffer overflow in Microsoft MSN Chat ActiveX Control, as used in MSN Messenger 4.5 and 4.6, and Exchange Instant Messenger 4.5 and 4.6, allows remote attackers to execute arbitrary code via a long ResDLL parameter in the MSNChat OCX.

Desbordamiento de búfer en el control ActiveX Microsoft MSN Chat, usado en MSN Messenger 4.5 y 4.6, y Exchange Instant Messenger 4.5 y 4.6, permite a atacantes remotos ejecutar código arbitrario mediante un parámetro ResDLL largo en el OCX MSNChat.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2002-03-19 CVE Reserved
  • 2002-05-29 CVE Published
  • 2024-02-08 EPSS Updated
  • 2024-08-08 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Msn Chat Control
Search vendor "Microsoft" for product "Msn Chat Control"
*-
Affected
Microsoft
Search vendor "Microsoft"
Msn Messenger
Search vendor "Microsoft" for product "Msn Messenger"
4.5
Search vendor "Microsoft" for product "Msn Messenger" and version "4.5"
-
Affected
Microsoft
Search vendor "Microsoft"
Msn Messenger
Search vendor "Microsoft" for product "Msn Messenger"
4.6
Search vendor "Microsoft" for product "Msn Messenger" and version "4.6"
-
Affected
Microsoft
Search vendor "Microsoft"
Msn Messenger Service For Exchange
Search vendor "Microsoft" for product "Msn Messenger Service For Exchange"
4.5
Search vendor "Microsoft" for product "Msn Messenger Service For Exchange" and version "4.5"
-
Affected
Microsoft
Search vendor "Microsoft"
Msn Messenger Service For Exchange
Search vendor "Microsoft" for product "Msn Messenger Service For Exchange"
4.6
Search vendor "Microsoft" for product "Msn Messenger Service For Exchange" and version "4.6"
-
Affected