cbcvebase.
CVE-2002-0150
published 2002-04-22

CVE-2002-0150: Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of…

PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
39.83%
98.5th percentile
Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscoproducts_ms02-018
microsoftinternet_information_server
microsoftinternet_information_services

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability targets HTTP header field values in IIS 4.0, 5.0, and 5.1 — monitor for anomalously large or malformed HTTP header field values sent to IIS servers, which may indicate an attempted buffer overflow to bypass safety checks
  • Affected products include Cisco applications installed on Microsoft operating systems using IIS — detection should cover IIS instances running as part of Cisco product deployments, not just standalone IIS servers
  • ·Affected IIS versions are 4.0, 5.0, and 5.1 — scope detection and patching efforts to these specific versions only
  • ·The vulnerability is in IIS itself, not in the Cisco product or application — Cisco products are affected only by virtue of running on IIS-enabled Windows hosts
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.