CVE-2002-0647 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 23.3% (pctl 98)
Patch early
A public exploit exists.
Description
Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 23.34% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-09-24 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer 5/6 Legacy Text Formatting - ActiveX Component Buffer Overflow | 2002-08-22 |
References
- http://www.iss.net/security_center/static/9935.php
- http://www.securityfocus.com/bid/5558
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-047
- http://www.iss.net/security_center/static/9935.php
- http://www.securityfocus.com/bid/5558
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-047
→ the Explorer · watch your stack · NVD