{"api_version":"1","generated_at":"2026-07-23T09:51:14+00:00","cve":"CVE-2002-0364","urls":{"html":"https://cve.report/CVE-2002-0364","api":"https://cve.report/api/cve/CVE-2002-0364.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0364","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0364"},"summary":{"title":"CVE-2002-0364","description":"Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka \"Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2002-07-03 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.iss.net/security_center/static/9327.php","name":"http://www.iss.net/security_center/static/9327.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database: iis-htr-chunked-encoding-bo (9327): Microsoft IIS ISAPI HTR chunked encoding heap buffer overflow","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A182","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A182","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/313819","name":"http://www.kb.cert.org/vuls/id/313819","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"CERT/CC Vulnerability Note VU#313819","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://online.securityfocus.com/archive/1/276767","name":"http://online.securityfocus.com/archive/1/276767","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus HOME Mailing List: BugTraq","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-028","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-028","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS02-028 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html","name":"http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A29","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A29","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=ntbugtraq&m=102392308608100&w=2","name":"http://marc.info/?l=ntbugtraq&m=102392308608100&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=102392069305962&w=2","name":"http://marc.info/?l=bugtraq&m=102392069305962&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4855","name":"http://www.securityfocus.com/bid/4855","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft IIS HTR Chunked Encoding Transfer Heap Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0364","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0364","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"364","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_information_server","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"364","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_information_services","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:49:28.198Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"4855","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4855"},{"name":"MS02-028","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-028"},{"name":"VU#313819","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/313819"},{"name":"20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow","tags":["mailing-list","x_refsource_NTBUGTRAQ","x_transferred"],"url":"http://marc.info/?l=ntbugtraq&m=102392308608100&w=2"},{"name":"iis-htr-chunked-encoding-bo(9327)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/9327.php"},{"name":"20020613 VNA - .HTR HEAP OVERFLOW","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://online.securityfocus.com/archive/1/276767"},{"name":"20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow [AD20020612]","tags":["mailing-list","x_refsource_VULNWATCH","x_transferred"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html"},{"name":"oval:org.mitre.oval:def:182","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A182"},{"name":"20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow [AD20020612]","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=102392069305962&w=2"},{"name":"oval:org.mitre.oval:def:29","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A29"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-06-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka \"Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2003-03-20T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"4855","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4855"},{"name":"MS02-028","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-028"},{"name":"VU#313819","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/313819"},{"name":"20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow","tags":["mailing-list","x_refsource_NTBUGTRAQ"],"url":"http://marc.info/?l=ntbugtraq&m=102392308608100&w=2"},{"name":"iis-htr-chunked-encoding-bo(9327)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/9327.php"},{"name":"20020613 VNA - .HTR HEAP OVERFLOW","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://online.securityfocus.com/archive/1/276767"},{"name":"20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow [AD20020612]","tags":["mailing-list","x_refsource_VULNWATCH"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html"},{"name":"oval:org.mitre.oval:def:182","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A182"},{"name":"20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow [AD20020612]","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=102392069305962&w=2"},{"name":"oval:org.mitre.oval:def:29","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A29"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0364","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka \"Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"4855","refsource":"BID","url":"http://www.securityfocus.com/bid/4855"},{"name":"MS02-028","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-028"},{"name":"VU#313819","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/313819"},{"name":"20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow","refsource":"NTBUGTRAQ","url":"http://marc.info/?l=ntbugtraq&m=102392308608100&w=2"},{"name":"iis-htr-chunked-encoding-bo(9327)","refsource":"XF","url":"http://www.iss.net/security_center/static/9327.php"},{"name":"20020613 VNA - .HTR HEAP OVERFLOW","refsource":"BUGTRAQ","url":"http://online.securityfocus.com/archive/1/276767"},{"name":"20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow [AD20020612]","refsource":"VULNWATCH","url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html"},{"name":"oval:org.mitre.oval:def:182","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A182"},{"name":"20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow [AD20020612]","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=102392069305962&w=2"},{"name":"oval:org.mitre.oval:def:29","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A29"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0364","datePublished":"2003-04-02T05:00:00.000Z","dateReserved":"2002-05-08T00:00:00.000Z","dateUpdated":"2024-08-08T02:49:28.198Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-07-03 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_information_server:4.0:*:*:*:*:*:*:*","matchCriteriaId":"5D47E9C4-5439-4A82-BBD8-D6B482B47E51"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_information_services:5.0:*:*:*:*:*:*:*","matchCriteriaId":"413C07EA-139F-4B7D-A58B-835BD2591FA0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"364","Ordinal":"1","Title":"CVE-2002-0364","CVE":"CVE-2002-0364","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"364","Ordinal":"1","NoteData":"Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka \"Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise.\"","Type":"Description","Title":"CVE-2002-0364"},{"CveYear":"2002","CveId":"364","Ordinal":"2","NoteData":"2003-04-02","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"364","Ordinal":"3","NoteData":"2003-03-19","Type":"Other","Title":"Modified"}]}}}