CVE-2002-0647: Buffer Overflow
Published Sep 24, 2002
·Updated
Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".
Affected Software
7 affected components
Microsoft Internet Explorer=5.01
Microsoft Internet Explorer=5.5-sp2
Microsoft Internet Explorer=5.5
Microsoft Internet Explorer=5.01-sp1
Microsoft Internet Explorer=5.01-sp2
Microsoft Internet Explorer=5.5-sp1
Microsoft Internet Explorer=6.0
Event History
Sep 24, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0647?
CVE-2002-0647 has a medium severity rating due to the potential for remote code execution.
2
How do I fix CVE-2002-0647?
To fix CVE-2002-0647, users should update Internet Explorer to a version that is not affected by the vulnerability.
3
What software is affected by CVE-2002-0647?
CVE-2002-0647 affects Microsoft Internet Explorer versions 5.01, 5.5, and 6.0.
4
What type of vulnerability is CVE-2002-0647?
CVE-2002-0647 is classified as a buffer overflow vulnerability.
5
Can CVE-2002-0647 be exploited remotely?
Yes, CVE-2002-0647 can be exploited remotely by attackers through specially formatted text.