CVE-2002-1486
Estado: ModificadaAlta (7.5)—
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 9.36%
- Percentil entre todas las CVEs puntuadas: 95
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0258.html
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0266.html
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0268.html
- http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0139.html
- http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0140.html
- http://www.iss.net/security_center/static/10150.php
- http://www.iss.net/security_center/static/10151.php
- http://www.iss.net/security_center/static/10163.php
- http://www.securityfocus.com/bid/5765
- http://www.securityfocus.com/bid/5769
- http://www.securityfocus.com/bid/5777
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0258.html
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0266.html
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0268.html
- http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0139.html
- http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0140.html
- http://www.iss.net/security_center/static/10150.php
- http://www.iss.net/security_center/static/10151.php
- http://www.iss.net/security_center/static/10163.php
- http://www.securityfocus.com/bid/5765
- http://www.securityfocus.com/bid/5769
- http://www.securityfocus.com/bid/5777
JSON original (NVD)
Mostrar
{
"id": "CVE-2002-1486",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2003-04-02T05:00:00.000",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2002-09/0258.html",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2002-09/0266.html",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2002-09/0268.html",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0139.html",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0140.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/10150.php",
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/10151.php",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/10163.php",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/5765",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/5769",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/5777",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2002-09/0258.html",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2002-09/0266.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2002-09/0268.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0139.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0140.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/10150.php",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/10151.php",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/10163.php",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/5765",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/5769",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/5777",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long \"raw 221\" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server."
},
{
"lang": "es",
"value": "Multiples desbordamiento de búfer en el componente IRC de Trillian 0.73 y 0.74 permite a servidores IRC remotos malintencionados causar la Denegación de Servicios y posiblemente la ejecución de código arbitrario mediante:\r\n\r\n una respuesta larga del servidor.\r\n un JOIN con un nombre de canal largo.\r\n un mensaje largo raw 221.\r\n un PRIVMSG con un alias (nick) largo.\r\n una respuesta larga de un servidor IDENT."
}
],
"lastModified": "2026-06-16T21:59:25.087",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cerulean_studios:trillian:0.73:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0376EA0-9F02-4987-A0A3-A79DE73512F7"
},
{
"criteria": "cpe:2.3:a:cerulean_studios:trillian:0.74:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "03C5DC92-EE8F-43A7-8F78-58D01FA4D4A1"
},
{
"criteria": "cpe:2.3:a:cerulean_studios:trillian:0.725:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E747537-D974-48C6-8EAA-6B26F3FBDDA3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}