CVE-2002-2258 describes a denial-of-service vulnerability in Moby NetSuite versions 1.0 and 1.2. Remote attackers can crash the application by sending an HTTP POST request with a malformed Content-Length header, specifically a large integer or non-numeric value, leading to an access violation after a failed atoi function call. This vulnerability has a CVSS score of 5.0, indicating a medium severity with low attack complexity and no authentication required, resulting in a partial availability impact. While not actively exploited in the wild and not listed in CISA's KEV catalog, an ExploitDB entry exists for a related buffer overflow, and the CVE has garnered significant community discussion, with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:mobydisk:netsuite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.