Vulnerabilities > CVE-2002-0079 - Heap Overflow vulnerability in Microsoft products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft
nessus
exploit available

Summary

Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.

Vulnerable Configurations

Part Description Count
Application
Microsoft
2

Exploit-Db

  • descriptionMicrosoft IIS 4.0/5.0 Chunked Encoding Transfer Heap Overflow Vulnerability (2). CVE-2002-0079. Remote exploit for windows platform
    idEDB-ID:21369
    last seen2016-02-02
    modified2002-04-14
    published2002-04-14
    reporterhsj
    sourcehttps://www.exploit-db.com/download/21369/
    titleMicrosoft IIS 4.0/5.0 Chunked Encoding Transfer Heap Overflow Vulnerability 2
  • descriptionMicrosoft IIS 4.0/5.0 Chunked Encoding Transfer Heap Overflow Vulnerability (4). CVE-2002-0079. Remote exploit for windows platform
    idEDB-ID:21371
    last seen2016-02-02
    modified2002-04-24
    published2002-04-24
    reporteryuange
    sourcehttps://www.exploit-db.com/download/21371/
    titleMicrosoft IIS 4.0/5.0 Chunked Encoding Transfer Heap Overflow Vulnerability 4
  • descriptionMicrosoft IIS 4.0/5.0 Chunked Encoding Transfer Heap Overflow Vulnerability (1). CVE-2002-0079. Remote exploit for windows platform
    idEDB-ID:21368
    last seen2016-02-02
    modified2002-04-10
    published2002-04-10
    reporterCHINANSL Security Team
    sourcehttps://www.exploit-db.com/download/21368/
    titleMicrosoft IIS 4.0/5.0 Chunked Encoding Transfer Heap Overflow Vulnerability 1
  • descriptionMicrosoft IIS 4.0/5.0 Chunked Encoding Transfer Heap Overflow Vulnerability (3). CVE-2002-0079. Remote exploit for windows platform
    idEDB-ID:21370
    last seen2016-02-02
    modified2002-04-10
    published2002-04-10
    reporterNeMeS||y
    sourcehttps://www.exploit-db.com/download/21370/
    titleMicrosoft IIS 4.0/5.0 Chunked Encoding Transfer Heap Overflow Vulnerability 3

Nessus

NASL familyWeb Servers
NASL idIIS_ASP_OVERFLOW.NASL
descriptionThere
last seen2020-06-01
modified2020-06-02
plugin id10935
published2002-04-10
reporterThis script is Copyright (C) 2002-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10935
titleMicrosoft IIS ASP ISAPI Filter Multiple Overflows

Oval

  • accepted2007-05-23T15:05:30.089-04:00
    classvulnerability
    contributors
    • nameTiffany Bergeron
      organizationThe MITRE Corporation
    • nameGlenn Strickland
      organizationSecure Elements, Inc.
    • nameJosh Turpin
      organizationSymantec Corporation
    descriptionBuffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.
    familywindows
    idoval:org.mitre.oval:def:16
    statusdeprecated
    submitted2004-01-14T12:00:00.000-04:00
    titleDEPRECATED: Windows NT IIS Chunked Encoding Buffer Overflow
    version29
  • accepted2010-12-20T04:00:43.992-05:00
    classvulnerability
    contributors
    • nameTiffany Bergeron
      organizationThe MITRE Corporation
    • nameGlenn Strickland
      organizationSecure Elements, Inc.
    • nameShane Shaffer
      organizationG2, Inc.
    • nameJosh Turpin
      organizationSymantec Corporation
    • nameSudhir Gandhe
      organizationTelos
    • nameShane Shaffer
      organizationG2, Inc.
    descriptionBuffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.
    familywindows
    idoval:org.mitre.oval:def:25
    statusdeprecated
    submitted2004-01-14T12:00:00.000-04:00
    titleDEPRECATED: Windows 2000 IIS Chunked Encoding Buffer Overflow
    version33

Saint

bid4485
descriptionMicrosoft IIS ASP chunked encoding buffer overflow
idweb_server_iis_multiple
osvdb768
titleiis_chunked_asp
typeremote