Skip to main content

CVE-2002-0208

5.0
CVSS v2.0 Base Score
2.00%
LOW RiskEPSS (78th percentile)

PGP Security PGPfire 7.1 for Windows alters the system's TCP/IP stack and modifies packets in ICMP error messages in a way that allows remote attackers to determine that the system is running PGPfire.

Published: 5/16/2002
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

5

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Score (Exploitation Probability)

2.00%LOW Exploitation Risk
78th percentile

This vulnerability has a 2.00% probability of being exploited in the next 30 days, ranking higher than 78% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-203)

CVE-2026-21484MEDIUM 5.3

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313, the password recovery endpoint returns different error messages depending on whether a username exists, so enabling username enumeration. Commit e287fab56089cf8fcea9ba579a3ecdeca0daa313 fixes this issue.

1/3/2026
CVE-2024-39891MEDIUM 5.3

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)

7/2/2024
CVE-2024-25714CRITICAL 9.8

In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which has constant-time execution.)

2/11/2024
CVE-2024-25191CRITICAL 9.8

php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.

2/8/2024
CVE-2024-25190CRITICAL 9.8

l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.

2/8/2024