Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2002-0392

87
FAUCET Score

CVE-2002-0392 describes a critical denial-of-service and potential arbitrary code execution vulnerability affecting Apache HTTP Server versions 1.3 through 1.3.24 and 2.0 through 2.0.36. This flaw, stemming from incorrect size handling in chunk-encoded HTTP requests, carries a CVSS score of 7.5, indicating a high severity with network-based exploitation requiring low attack complexity and no authentication. Exploit intelligence shows readily available public exploit code, including Metasploit modules and ExploitDB entries, though it is not currently listed on the CISA KEV catalog or the Hot List. Despite its age and the availability of exploits, there is no recent community discussion or media coverage, which is typical for many older CVEs.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.2.2, <= 1.3.24CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
>= 2.0.0, <= 2.0.36CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
2.2CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:2.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
95.03%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: Apache Win32 Chunked Encoding · Jun 19, 2002
ExploitDB: EDB-16782 · Jul 7, 2010
This CVE's current EPSS score of 0.9503 is in the 100th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux AS (Advanced Server) version 2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux 6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux 7.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux 7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux 7.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux 7.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Secure Web Server 3.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Stronghold 3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Stronghold 4
View patch
redhatpatch availablevia redhat_api
Product: Stronghold 4 for Red Hat Enterprise Linux
View patch

Vendor Advisories (1)

redhatCVE-2002-0392Moderate

security flaw

Jun 17, 2002

References

ftp.caldera.com / pub/security/OpenLinux/CSSA-2002-029.0.txt
Broken Link
ftp.caldera.com / pub/updates/OpenServer/CSSA-2002-SCO.32
Broken Link
ftp.caldera.com / pub/updates/OpenUNIX/CSSA-2002-SCO.31
Broken Link
patches.sgi.com / support/free/security/advisories/20020605-01-A
Broken Link
patches.sgi.com / support/free/security/advisories/20020605-01-I
Broken Link
archives.neohapsis.com / archives/bugtraq/2002-06/0235.html
Broken Link
archives.neohapsis.com / archives/bugtraq/2002-06/0266.html
Broken Link
distro.conectiva.com / atualizacoes
Broken Link
frontal2.mandriva.com / security/advisories
Broken Link
httpd.apache.org / info/security_bulletin_20020617.txt
Vendor Advisory
online.securityfocus.com / advisories/4240
Broken LinkThird Party AdvisoryVDB Entry
online.securityfocus.com / advisories/4257
Broken LinkThird Party AdvisoryVDB Entry
online.securityfocus.com / archive/1/278149
Broken LinkThird Party AdvisoryVDB Entry
rhn.redhat.com / errata/RHSA-2002-103.html
Broken Link
rhn.redhat.com / errata/RHSA-2002-117.html
Broken Link
rhn.redhat.com / errata/RHSA-2002-118.html
Broken Link
secunia.com / advisories/21917
Third Party Advisory
lists.apache.org / thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rd00b45b93fda4a5bd013b28587207d0e00f99f6e3308dbb6025f3b01%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
www2.itrc.hp.com / service/cki/docDisplay.do
Broken Link
cert.org / advisories/CA-2002-17.html
PatchThird Party AdvisoryUS Government Resource
debian.org / security/2002/dsa-131
Third Party Advisory
debian.org / security/2002/dsa-132
Third Party Advisory
debian.org / security/2002/dsa-133
Third Party Advisory
frsirt.com / english/advisories/2006/3598
Third Party Advisory
iss.net / security_center/static/9249.php
Broken Link
kb.cert.org / vuls/id/944335
Third Party AdvisoryUS Government Resource
linuxsecurity.com / advisories/other_advisory-2137.html
Third Party Advisory
novell.com / linux/security/advisories/2002_22_apache.html
Broken Link
osvdb.org / 838
Broken Link
redhat.com / support/errata/RHSA-2002-126.html
Third Party Advisory
redhat.com / support/errata/RHSA-2002-150.html
Third Party Advisory
redhat.com / support/errata/RHSA-2003-106.html
Third Party Advisory
securityfocus.com / bid/20005
Third Party AdvisoryVDB Entry
securityfocus.com / bid/5033
Third Party AdvisoryVDB Entry