peter bassill · operator
$ cve CVE-2002-0647 JSON

CVE-2002-0647 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 23.3% (pctl 98)

Patch early

A public exploit exists.

Description

Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS23.34% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2002-09-24
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD