Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2002-1616

34
FAUCET Score

CVE-2002-1616 describes multiple buffer overflow vulnerabilities in HP Tru64 UNIX versions 5.1a, 5.1, 5.0a, 4.0g, and 4.0f. These flaws, present in utilities like su, chsh, and passwd, allow local users to escalate privileges to root. With a CVSS score of 7.2, this vulnerability is considered highly severe due to its local attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While not on the CISA KEV catalog, an ExploitDB entry exists for a stack overflow in 'su', and the vulnerability has garnered significant community discussion, though no active exploitation or media coverage is reported.

Impacted Technologies

VendorProductVersion(s)CPE
4.0fCPE matchmatch criteria
cpe:2.3:o:hp:tru64:4.0f:*:*:*:*:*:*:*
4.0gCPE matchmatch criteria
cpe:2.3:o:hp:tru64:4.0g:*:*:*:*:*:*:*
5.0aCPE matchmatch criteria
cpe:2.3:o:hp:tru64:5.0a:*:*:*:*:*:*:*
5.1CPE matchmatch criteria
cpe:2.3:o:hp:tru64:5.1:*:*:*:*:*:*:*
5.1afCPE matchmatch criteria
cpe:2.3:o:hp:tru64:5.1af:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.2HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
3.90%
Probability of exploitation in next 30 days
EPSS Percentile
89.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-259 · Jan 26, 2001
This CVE's current EPSS score of 0.0389 is in the 97th percentile among its peer group of 3,237 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

archives.neohapsis.com / archives/fulldisclosure/2002-q3/1203.html
archives.neohapsis.com / archives/tru64/2002-q3/0019.html
exchange.xforce.ibmcloud.com / vulnerabilities/10614
exchange.xforce.ibmcloud.com / vulnerabilities/11620
blacksheepnetworks.com / security/hack/tru64/TRU64_su.txt
Exploit
kb.cert.org / vuls/id/137555
Third Party AdvisoryUS Government Resource
kb.cert.org / vuls/id/177067
Third Party AdvisoryUS Government Resource
kb.cert.org / vuls/id/193347
PatchUS Government Resource
kb.cert.org / vuls/id/671627
Third Party AdvisoryUS Government Resource
kb.cert.org / vuls/id/864083
US Government Resource
securityfocus.com / archive/1/290115
Vendor Advisory
securityfocus.com / bid/5379
Vendor Advisory
securityfocus.com / bid/5380
Patch
securityfocus.com / bid/5381
Patch
securityfocus.com / bid/5382
Patch