CVE-2002-0370 - CVE House
Back to Database
Status published High CVE-2002-0370

Buffer overflow in the ZIP capability for multiple products allows...

Vulnerability Description

Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2002-0370

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

allume systems division

View all reports →

Affected Software

stuffit expander, lotus notes, keyview viewing sdk, winzip, windows 98 plus pack, windows me, windows xp
Vulnerable Versions:
6.5.2, 0, 5.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.9a, 5.0.10, 5.0.11, r5, r6, gold, 7.0

Timeline

Official Publish: October 5th, 2002
Last Modified: August 8th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.