← Vulnerability feed

Vulnerability record · CVE-2002-1127 · published 4 October 2002

CVE-2002-1127: Digital osf 1 vulnerability

DDigital · Osf 1

Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter.

7.2 CVSS 2.0 High EPSS 0.46% · top 62.6%
7.2CVSS 2.0 base score
0.46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1127 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-1999-0073Sgi irix vulnerabilityTelnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries …EPSS 3.1%7.2CVE-2002-1128Digital osf 1 vulnerabilityBuffer overflow in inc mail utility for Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long MH environment variable.EPSS 0.46%7.2CVE-2002-1129Compaq tru64 vulnerabilityBuffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument.EPSS 1.0%7.2CVE-1999-0131Eric allman sendmail vulnerabilityBuffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.EPSS 0.57%7.2CVE-1999-0138Apple a ux vulnerabilityThe suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.EPSS 0.70%5.0CVE-1999-0128Oversized ICMP ping packets cause denial of service (Ping o' Death)Sending oversized ICMP ping packets can crash or hang affected TCP/IP stacks, a flaw known as Ping o' Death. It matters because a single unauthentica…EPSS 75%analysed4.6CVE-1999-0303Digital osf 1 vulnerabilityBuffer overflow in BNU UUCP daemon (uucpd) through long hostnames.EPSS 0.35%4.6CVE-1999-1103Digital osf 1 vulnerabilitydxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2002-1127), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.