CVE-2002-1349 describes a buffer overflow vulnerability in the pop3trap.exe component of Trend Micro PC-cillin 2000, 2002, and 2003. This flaw allows a local attacker to execute arbitrary code by sending a specially crafted, long input string to the POP3 service on TCP port 110. With a CVSS score of 4.6, it is considered a medium-severity vulnerability, requiring local access but having a low attack complexity, potentially leading to partial confidentiality, integrity, and availability impacts. While no active exploitation is reported and it is not in the KEV catalog, a public exploit (EDB-22082) exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
corporate_5.02CPE matchmatch criteria | cpe:2.3:a:trend_micro:officescan:corporate_5.02:*:*:*:*:*:*:* | ||
2000CPE matchmatch criteria | cpe:2.3:a:trend_micro:pc-cillin:2000:*:*:*:*:*:*:* | ||
2002CPE matchmatch criteria | cpe:2.3:a:trend_micro:pc-cillin:2002:*:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:trend_micro:pc-cillin:2003:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.