← Vulnerability feed

Vulnerability record · CVE-2002-1128 · published 4 October 2002

CVE-2002-1128: Digital osf 1 vulnerability

DDigital · Osf 1

Buffer overflow in inc mail utility for Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long MH environment variable.

7.2 CVSS 2.0 High EPSS 0.46% · top 62.6%
7.2CVSS 2.0 base score
0.46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in inc mail utility for Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long MH environment variable.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1128 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-1999-0046rlogin buffer overflow via TERM environment variableThe rlogin program contains a classic buffer overflow (CWE-120) triggered through the TERM environment variable. Because rlogin is a network login se…EPSS 52%analysed10.0CVE-1999-0073Sgi irix vulnerabilityTelnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries …EPSS 3.1%10.0CVE-1999-1032Digital ultrix vulnerabilityVulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.EPSS 2.4%7.5CVE-1999-0170Digital ultrix vulnerabilityRemote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.EPSS 19%7.2CVE-2002-1127Digital osf 1 vulnerabilityBuffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter.EPSS 0.46%7.2CVE-2002-1129Compaq tru64 vulnerabilityBuffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument.EPSS 1.0%7.2CVE-1999-0131Eric allman sendmail vulnerabilityBuffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.EPSS 0.57%7.2CVE-1999-0138Apple a ux vulnerabilityThe suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.EPSS 0.70%

Source: NIST National Vulnerability Database (record CVE-2002-1128), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.