← Vulnerability feed

Vulnerability record · CVE-2002-2002 · published 31 December 2002

CVE-2002-2002: Compaq tru64 vulnerability

CCompaq · Tru64

Buffer overflow in libc in Compaq Tru64 4.0F, 5.0, 5.1 and 5.1A allows attackers to execute arbitrary code via long (1) LANG and (2) LOCPATH environment variables.

7.5 CVSS 2.0 High EPSS 2.7% · top 14.8%
7.5CVSS 2.0 base score
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in libc in Compaq Tru64 4.0F, 5.0, 5.1 and 5.1A allows attackers to execute arbitrary code via long (1) LANG and (2) LOCPATH environment variables.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-2002 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2003-0694Sendmail prescan buffer overflow allows remote code executionThe prescan function in Sendmail 8.12.9 contains a buffer overflow reachable through crafted email addresses, as demonstrated via the parseaddr funct…EPSS 66%analysed10.0CVE-2003-0196Samba vulnerabilityMultiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by …EPSS 23%10.0CVE-2003-0201Samba call_trans2open buffer overflow allows remote code executionA buffer overflow exists in the call_trans2open function in trans2.c in Samba 2.2.x before 2.2.8a, Samba 2.0.10 and earlier 2.0.x, and Samba-TNG befo…EPSS 85%analysed10.0CVE-2003-0161Sendmail vulnerabilityThe prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int t…EPSS 39%10.0CVE-2002-0679Caldera unixware vulnerabilityBuffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code …EPSS 23%7.5CVE-2003-0724Compaq tru64 vulnerabilityssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local a…EPSS 0.85%7.5CVE-2002-1202Compaq tru64 vulnerabilityUnknown vulnerability in routed for HP Tru64 UNIX V4.0F through V5.1A allows local and remote attackers to read arbitrary files.EPSS 1.6%7.5CVE-2002-0677Caldera unixware vulnerabilityCDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, …EPSS 6.6%

Source: NIST National Vulnerability Database (record CVE-2002-2002), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.