← Back to browse · API

CVE-2002-0391

Severity
CRITICAL
CVSS
9.8
EPSS
0.58133
Risk score
59.55
CISA KEV
No
PoC
No
Published
2003-04-02
Modified
2025-01-16
First seen
2026-08-07
Aliases
EUVD-2002-0388, GHSA-2QF2-Q2GJ-R6V2
Products
n/a:n/a n/a
Sources
euvd EUVD-2002-0388

Description

Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.

References