Vulnerabilities > CVE-2002-0693 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 46 |
Exploit-Db
description | MS Windows XP/2000/NT 4 Help Facility ActiveX Control Buffer Overflow. CVE-2002-0693. Remote exploit for windows platform |
id | EDB-ID:21902 |
last seen | 2016-02-02 |
modified | 2002-10-07 |
published | 2002-10-07 |
reporter | ipxodi |
source | https://www.exploit-db.com/download/21902/ |
title | Microsoft Windows 2000/XP/NT 4 - Help Facility ActiveX Control Buffer Overflow |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS02-055.NASL |
description | The remote host contains a version of the HTML Helpfacility ActiveX control module that could allow an attacker to execute arbitrary code on the remote host by constructing a malicious web page and enticing a victim to visit it. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11147 |
published | 2002-10-24 |
reporter | This script is Copyright (C) 2002-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11147 |
title | MS02-055: Unchecked Buffer in Windows Help Facility Could Enable Code Execution (323255) |
code |
|
Oval
accepted | 2011-05-16T04:02:52.166-04:00 | ||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||
description | Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function. | ||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||
id | oval:org.mitre.oval:def:374 | ||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||
submitted | 2003-09-18T12:00:00.000-04:00 | ||||||||||||||||||||||||
title | HTML Help ActiveX Control Buffer Overflow | ||||||||||||||||||||||||
version | 69 |
References
- http://www.iss.net/security_center/static/10253.php
- http://www.securityfocus.com/bid/5874
- http://marc.info/?l=bugtraq&m=103365849505409&w=2
- http://marc.info/?l=bugtraq&m=103419115517344&w=2
- http://marc.info/?l=bugtraq&m=103435279404182&w=2
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A374
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-055