← Vulnerability feed

Vulnerability record · CVE-2002-0620 · published 3 July 2002

CVE-2002-0620: Microsoft commerce server vulnerability

Microsoft · Commerce Server

Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.

5.0 CVSS 2.0 Medium EPSS 12% · top 4.0%
5.0CVSS 2.0 base score
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0620 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed8.8CVE-2012-0158Microsoft MSCOMCTL.OCX ActiveX controls remote code executionThe ListView, ListView2, TreeView and TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls fail to handle crafted input, allowing memory…KEVEPSS 100%analysed9.3CVE-2007-1201Microsoft biztalk server code injection vulnerabilityUnspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary c…EPSS 29%7.5CVE-2006-1257Microsoft commerce server vulnerabilityThe sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging i…EPSS 30%7.5CVE-2002-0622Microsoft commerce server vulnerabilityThe Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the comma…EPSS 19%7.5CVE-2002-0623Microsoft commerce server vulnerabilityBuffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long auth…EPSS 20%7.5CVE-2002-0050Microsoft commerce server vulnerabilityBuffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 allows remote attackers to execute arbitrary code via long authenticatio…EPSS 13%5.0CVE-2002-0621Microsoft commerce server vulnerabilityBuffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the proc…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2002-0620), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.