Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2002-0366 | First vendor Publication | 2002-07-03 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.2 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0366 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:61 | |||
Oval ID: | oval:org.mitre.oval:def:61 | ||
Title: | Windows NT Remote Access Service Phonebook Buffer Overflow | ||
Description: | Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2002-0366 | Version: | 1 |
Platform(s): | Microsoft Windows NT | Product(s): | Remote Access Service (RAS) |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:63 | |||
Oval ID: | oval:org.mitre.oval:def:63 | ||
Title: | Windows 2000 Remote Access Service Phonebook Buffer Overflow | ||
Description: | Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2002-0366 | Version: | 6 |
Platform(s): | Microsoft Windows 2000 | Product(s): | Remote Access Service (RAS) |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
837 | Microsoft Windows RAS Phonebook dial-up String Overflow |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2002-06-13 | Name : A local user can elevate his privileges. File : smb_nt_ms02-029.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:54 |
|
2024-11-28 12:05:00 |
|
2024-08-02 12:02:10 |
|
2024-08-02 01:01:19 |
|
2024-02-02 01:01:58 |
|
2024-02-01 12:01:20 |
|
2023-09-05 12:01:53 |
|
2023-09-05 01:01:12 |
|
2023-09-02 12:01:54 |
|
2023-09-02 01:01:12 |
|
2023-08-12 12:02:15 |
|
2023-08-12 01:01:12 |
|
2023-08-11 12:01:58 |
|
2023-08-11 01:01:13 |
|
2023-08-06 12:01:49 |
|
2023-08-06 01:01:13 |
|
2023-08-04 12:01:53 |
|
2023-08-04 01:01:12 |
|
2023-07-14 12:01:51 |
|
2023-07-14 01:01:13 |
|
2023-03-29 01:01:50 |
|
2023-03-28 12:01:18 |
|
2022-10-11 12:01:39 |
|
2022-10-11 01:01:06 |
|
2021-05-04 12:01:39 |
|
2021-04-22 01:01:47 |
|
2020-05-23 00:14:57 |
|
2019-05-09 12:01:11 |
|
2019-04-30 21:19:17 |
|
2018-10-13 00:22:25 |
|
2017-10-10 09:23:24 |
|
2016-04-26 12:08:25 |
|
2014-02-17 10:24:36 |
|
2013-05-11 12:09:09 |
|