VYPR
Unrated severityNVD Advisory· Published Apr 22, 2002· Updated Jun 16, 2026

CVE-2002-0152

CVE-2002-0152

Description

Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

20
  • cpe:2.3:a:microsoft:entourage:2001:*:macos:*:*:*:*:*+ 2 more
    • cpe:2.3:a:microsoft:entourage:2001:*:macos:*:*:*:*:*
    • cpe:2.3:a:microsoft:entourage:v._x:*:macos:*:*:*:*:*
    • (no CPE)range: v. X, 2001
  • Microsoft/Excel3 versions
    cpe:2.3:a:microsoft:excel:2001:*:mac_os_x:*:*:*:*:*+ 2 more
    • cpe:2.3:a:microsoft:excel:2001:*:mac_os_x:*:*:*:*:*
    • cpe:2.3:a:microsoft:excel:x:*:mac_os_x:*:*:*:*:*
    • (no CPE)range: v. X, 2001
  • cpe:2.3:a:microsoft:ie:5.1:*:mac_os:*:*:*:*:*
  • Microsoft/Office3 versions
    cpe:2.3:a:microsoft:office:2001:*:macos:*:*:*:*:*+ 2 more
    • cpe:2.3:a:microsoft:office:2001:*:macos:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2001:sr1:mac_os:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:v.x:*:mac:*:*:*:*:*
  • cpe:2.3:a:microsoft:outlook_express:5.0.1:*:macos:*:*:*:*:*+ 4 more
    • cpe:2.3:a:microsoft:outlook_express:5.0.1:*:macos:*:*:*:*:*
    • cpe:2.3:a:microsoft:outlook_express:5.0.2:*:macos:*:*:*:*:*
    • cpe:2.3:a:microsoft:outlook_express:5.0.3:*:macos:*:*:*:*:*
    • cpe:2.3:a:microsoft:outlook_express:5.0:*:macos:*:*:*:*:*
    • (no CPE)range: 5.0-5.0.2
  • cpe:2.3:a:microsoft:powerpoint:2001:*:macos:*:*:*:*:*+ 3 more
    • cpe:2.3:a:microsoft:powerpoint:2001:*:macos:*:*:*:*:*
    • cpe:2.3:a:microsoft:powerpoint:98:*:macos:*:*:*:*:*
    • cpe:2.3:a:microsoft:powerpoint:v.x:*:macos:*:*:*:*:*
    • (no CPE)range: v. X, 2001, 98
  • Range: = 5.1

Patches

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

5

News mentions

0

No linked articles in our index yet.