← Vulnerability feed

Vulnerability record · CVE-2002-0684 · published 12 August 2002

CVE-2002-0684: Gnu glibc vulnerability

Gnu · Glibc

Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.

7.5 CVSS 2.0 High EPSS 5.9% · top 7.1%
7.5CVSS 2.0 base score
5.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0684 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-4911GNU C Library ld.so GLIBC_TUNABLES heap buffer overflowThe GNU C Library dynamic loader ld.so mishandles the GLIBC_TUNABLES environment variable, causing a heap-based buffer overflow and out-of-bounds wri…KEVEPSS 81%analysed10.0CVE-2015-0235glibc gethostbyname heap buffer overflow (GHOST)CVE-2015-0235 is a heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2 and other 2.x versions before 2.18. It is reach…EPSS 95%analysed10.0CVE-2008-0122Isc bind vulnerabilityOff-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows…EPSS 12%10.0CVE-2001-0010Isc bind vulnerabilityBuffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.EPSS 32%10.0CVE-2001-0011Isc bind vulnerabilityBuffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.EPSS 7.7%10.0CVE-2001-0013Isc bind vulnerabilityFormat string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.EPSS 11%10.0CVE-2000-1029Isc bind vulnerabilityBuffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query.EPSS 14%10.0CVE-1999-0837Isc bind vulnerabilityDenial of service in BIND by improperly closing TCP sessions via so_linger.EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2002-0684), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.