{"api_version":"1","generated_at":"2026-07-23T04:00:04+00:00","cve":"CVE-2002-1869","urls":{"html":"https://cve.report/CVE-2002-1869","api":"https://cve.report/api/cve/CVE-2002-1869.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-1869","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-1869"},"summary":{"title":"CVE-2002-1869","description":"Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an application such as Microsoft's Event Viewer.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-667","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"3.3","severity":"LOW","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":3.3,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://securitytracker.com/id?1005517","name":"http://securitytracker.com/id?1005517","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Third Party Advisory","VDB Entry"],"title":"EventSave/EventSave+ File Access Error May Cause Events to Be Lost in Certain Cases - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.heysoft.de/nt/eventlog/hsb01e.htm","name":"http://www.heysoft.de/nt/eventlog/hsb01e.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch"],"title":"Bug in EventSave and EventSave+","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/10535.php","name":"http://www.iss.net/security_center/static/10535.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch"],"title":"ISS X-Force Database: eventsave-event-log-loss (10535): EventSave and EventSave+ could allow event loss from the Windows NT log","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6095","name":"http://www.securityfocus.com/bid/6095","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Third Party Advisory","VDB Entry"],"title":"Heysoft EventSave Event Log Notification Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-1869","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-1869","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"1869","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"heysoft","cpe5":"eventsave","cpe6":"5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1869","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"heysoft","cpe5":"eventsave","cpe6":"5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1869","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"heysoft","cpe5":"eventsave\\+","cpe6":"5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1869","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"heysoft","cpe5":"eventsave\\+","cpe6":"5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:43:33.137Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"6095","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6095"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.heysoft.de/nt/eventlog/hsb01e.htm"},{"name":"eventsave-event-log-loss(10535)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/10535.php"},{"name":"1005517","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1005517"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an application such as Microsoft's Event Viewer."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-06-28T04:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"6095","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6095"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.heysoft.de/nt/eventlog/hsb01e.htm"},{"name":"eventsave-event-log-loss(10535)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/10535.php"},{"name":"1005517","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1005517"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-1869","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an application such as Microsoft's Event Viewer."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"6095","refsource":"BID","url":"http://www.securityfocus.com/bid/6095"},{"name":"http://www.heysoft.de/nt/eventlog/hsb01e.htm","refsource":"CONFIRM","url":"http://www.heysoft.de/nt/eventlog/hsb01e.htm"},{"name":"eventsave-event-log-loss(10535)","refsource":"XF","url":"http://www.iss.net/security_center/static/10535.php"},{"name":"1005517","refsource":"SECTRACK","url":"http://securitytracker.com/id?1005517"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-1869","datePublished":"2005-06-28T04:00:00.000Z","dateReserved":"2005-06-28T04:00:00.000Z","dateUpdated":"2024-09-16T16:18:31.740Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-667","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":3.3,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:heysoft:eventsave:5.1:*:*:*:*:*:*:*","matchCriteriaId":"F3904208-D3EA-4F05-8F6A-58C568B9DBAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:heysoft:eventsave:5.2:*:*:*:*:*:*:*","matchCriteriaId":"F602B9C7-4B4B-4609-8557-9AC9C6A34604"},{"vulnerable":true,"criteria":"cpe:2.3:a:heysoft:eventsave\\+:5.1:*:*:*:*:*:*:*","matchCriteriaId":"24B81803-B579-4BD1-8661-9CE8C6BE5E47"},{"vulnerable":true,"criteria":"cpe:2.3:a:heysoft:eventsave\\+:5.2:*:*:*:*:*:*:*","matchCriteriaId":"83A27D19-2E44-4444-BC50-970FEB6DA0A9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"1869","Ordinal":"1","Title":"CVE-2002-1869","CVE":"CVE-2002-1869","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"1869","Ordinal":"1","NoteData":"Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an application such as Microsoft's Event Viewer.","Type":"Description","Title":"CVE-2002-1869"},{"CveYear":"2002","CveId":"1869","Ordinal":"2","NoteData":"2005-06-28","Type":"Other","Title":"Published"}]}}}