CVE-2002-1930 describes a buffer overflow vulnerability in AN HTTPd versions 1.38 through 1.4.1c, allowing remote attackers to execute arbitrary code by sending a SOCKS4 request with an excessively long username. This vulnerability carries a CVSS score of 7.5, indicating high severity, as it can be exploited remotely with low complexity to achieve partial confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation in the wild or Metasploit/Nuclei modules, an exploit for this flaw is publicly available on ExploitDB. Despite its age and the availability of exploit code, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.38CPE matchmatch criteria | cpe:2.3:a:an:an-httpd:1.38:*:*:*:*:*:*:* | ||
1.39CPE matchmatch criteria | cpe:2.3:a:an:an-httpd:1.39:*:*:*:*:*:*:* | ||
1.40CPE matchmatch criteria | cpe:2.3:a:an:an-httpd:1.40:*:*:*:*:*:*:* | ||
1.41CPE matchmatch criteria | cpe:2.3:a:an:an-httpd:1.41:*:*:*:*:*:*:* | ||
1.41bCPE matchmatch criteria | cpe:2.3:a:an:an-httpd:1.41b:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.