Your RSA-2048 keys break in 2030. Find every one of them before attackers do.

CVE-2002-0392

Published
Jul 3, 2002
Updated
Apr 10, 2026
Affected
0 pkgs
Patched
None yet
Exploits
4 known

EPSS Exploitation Probability

via FIRST.org ↗
95.6%probability of exploitation in next 30 days
Very High Risk100th percentile+41.67%
41.4%60.9%80.5%100.0%59.3%95.6%Dec 25Apr 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Description

Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.

Exploits & PoCs
4

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

EDB-16782remotewindows_x86✓ Verified

Apache (Windows x86) - Chunked Encoding (Metasploit)

by Metasploit · Jul 7, 2010

EDB-21560remotemultiple✓ Verified

Apache 1.x/2.0.x - Chunked-Encoding Memory Corruption (2)

by Gobbles Security · Jun 17, 2002

EDB-21559remotemultiple✓ Verified

Apache 1.x/2.0.x - Chunked-Encoding Memory Corruption (1)

by Gobbles Security · Jun 17, 2002

Frequently Asked Questions

Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
O3 Security · Impact-Aware SCA

Is CVE-2002-0392 in your stack?

O3 detects CVE-2002-0392 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.