peter bassill · operator
$ cve CVE-2002-1347 JSON

CVE-2002-1347

9.8
CRITICAL · CVSS 3.1 · EPSS 7.1% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.08% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-131
On CISA KEVno
Public exploitnone known
Published2002-12-18
Last modified2026-06-16

Affected (3)

VendorProduct
applemac os x
applemac os x server
cyrusimapcyrus sasl

References

→ the Explorer  ·  watch your stack  ·  NVD