{
    "id": "CVE-2002-0391",
    "published": "2002-08-12 04:00:00",
    "last_modified": "2026-06-16 21:57:20",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-190",
    "description": "Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.",
    "epss_score": "0.58133",
    "epss_percentile": "0.99070",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-02 18:17:03",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "EPSS 58.1% — above the 10% action threshold."
    },
    "products": [
        {
            "vendor": "freebsd",
            "product": "freebsd"
        },
        {
            "vendor": "microsoft",
            "product": "windows_2000"
        },
        {
            "vendor": "microsoft",
            "product": "windows_nt"
        },
        {
            "vendor": "microsoft",
            "product": "windows_xp"
        },
        {
            "vendor": "openbsd",
            "product": "openbsd"
        },
        {
            "vendor": "sun",
            "product": "solaris"
        },
        {
            "vendor": "sun",
            "product": "sunos"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-055.0.txt",
        "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-011.txt.asc",
        "ftp://patches.sgi.com/support/free/security/advisories/20020801-01-A",
        "ftp://patches.sgi.com/support/free/security/advisories/20020801-01-P",
        "http://archives.neohapsis.com/archives/aix/2002-q4/0002.html",
        "http://archives.neohapsis.com/archives/bugtraq/2002-07/0514.html",
        "http://archives.neohapsis.com/archives/hp/2002-q3/0077.html",
        "http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20823",
        "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000515",
        "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000535",
        "http://marc.info/?l=bugtraq&m=102813809232532&w=2",
        "http://marc.info/?l=bugtraq&m=102821785316087&w=2",
        "http://marc.info/?l=bugtraq&m=102821928418261&w=2",
        "http://marc.info/?l=bugtraq&m=102831443208382&w=2",
        "http://marc.info/?l=bugtraq&m=103158632831416&w=2",
        "http://online.securityfocus.com/advisories/4402",
        "http://online.securityfocus.com/archive/1/285740",
        "http://rhn.redhat.com/errata/RHSA-2002-166.html",
        "http://rhn.redhat.com/errata/RHSA-2002-172.html",
        "http://www.cert.org/advisories/CA-2002-25.html",
        "http://www.debian.org/security/2002/dsa-142",
        "http://www.debian.org/security/2002/dsa-143",
        "http://www.debian.org/security/2002/dsa-146",
        "http://www.debian.org/security/2002/dsa-149",
        "http://www.debian.org/security/2003/dsa-333"
    ]
}