← Vulnerability feed

Vulnerability record · CVE-2002-0155 · published 29 May 2002

CVE-2002-0155: Microsoft msn chat control vulnerability

Microsoft · Msn Chat Control

Buffer overflow in Microsoft MSN Chat ActiveX Control, as used in MSN Messenger 4.5 and 4.6, and Exchange Instant Messenger 4.5 and 4.6, allows remote attackers to execute arbitrary code via a long ResDLL parameter in the MSNChat OCX.

7.5 CVSS 2.0 High EPSS 24% · top 2.2%
7.5CVSS 2.0 base score
24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Microsoft MSN Chat ActiveX Control, as used in MSN Messenger 4.5 and 4.6, and Exchange Instant Messenger 4.5 and 4.6, allows remote attackers to execute arbitrary code via a long ResDLL parameter in the MSNChat OCX.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0155 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0597libpng PNG chunk buffer overflows allow remote code executionlibpng 1.2.5 and earlier contain multiple buffer overflows in the png_handle_tRNS, png_handle_sBIT and png_handle_hIST functions, which fail to valid…EPSS 83%analysed9.3CVE-2007-2931Microsoft MSN/Live Messenger heap buffer overflow in video chatA heap-based buffer overflow exists in Microsoft MSN Messenger 6.2, 7.0, 7.5 and Windows Live Messenger 8.0, triggered through unspecified vectors in…EPSS 55%analysed7.5CVE-2005-0562Microsoft msn messenger vulnerabilityGIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an imp…EPSS 23%5.0CVE-2007-3436Microsoft msn messenger vulnerabilityMicrosoft MSN Messenger 4.7 on Windows XP allows remote attackers to cause a denial of service (resource consumption) via a flood of SIP INVITE reque…EPSS 13%5.0CVE-2004-0122Microsoft msn messenger vulnerabilityMicrosoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.EPSS 22%5.0CVE-2002-1698Microsoft msn messenger vulnerabilityBuffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) …EPSS 16%5.0CVE-2002-1831Microsoft msn messenger vulnerabilityMicrosoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-…EPSS 22%5.0CVE-2002-0472Microsoft msn messenger vulnerabilityMSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attack…EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2002-0155), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.