← Vulnerability feed

Vulnerability record · CVE-2002-0702 · published 26 July 2002

CVE-2002-0702: Isc dhcpd vulnerability

Isc · Dhcpd

Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE option enabled, allow remote malicious DNS servers to execute arbitrary code via format strings in a DNS server response.

10.0 CVSS 2.0 High EPSS 31% · top 1.8%
10.0CVSS 2.0 base score
31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE option enabled, allow remote malicious DNS servers to execute arbitrary code via format strings in a DNS server response.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0702 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-1006Isc dhcpd vulnerabilityFormat string vulnerability in the log functions in dhcpd for dhcp 2.x allows remote DNS servers to execute arbitrary code via certain DNS messages, …EPSS 8.0%10.0CVE-2004-0460ISC DHCP dhcpd logging buffer overflow via hostname optionsISC DHCP 3.0.1rc12 and 3.0.1rc13 contain a buffer overflow in the DHCP daemon's logging capability. Multiple hostname options in DISCOVER, OFFER, REQ…EPSS 45%analysed10.0CVE-2004-0461Infoblox dns one appliance vulnerabilityThe DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C includ…EPSS 17%7.5CVE-2019-6470Isc dhcpd vulnerabilityThere had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in …EPSS 8.8%7.5CVE-2003-0026Isc dhcpd vulnerabilityMultiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 thr…EPSS 19%5.0CVE-2006-3122Isc dhcpd vulnerabilityThe supersede_lease function in memory.c in ISC DHCP (dhcpd) server 2.0pl5 allows remote attackers to cause a denial of service (application crash) v…EPSS 4.0%5.0CVE-2003-0039Isc dhcpd vulnerabilityISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a …EPSS 8.0%

Source: NIST National Vulnerability Database (record CVE-2002-0702), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.