Unrated severityNVD Advisory· Published Dec 31, 2002· Updated Apr 16, 2026
CVE-2002-1831
CVE-2002-1831
Description
Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.
Affected products
8cpe:2.3:a:microsoft:msn_messenger:1.0:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:microsoft:msn_messenger:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:msn_messenger:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:msn_messenger:2.2:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:msn_messenger:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:msn_messenger:3.6:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:msn_messenger:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:msn_messenger:4.5:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:msn_messenger:4.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.