# CVE-2002-0525

## Summary

- **CVE ID:** CVE-2002-0525
- **Severity:** UNKNOWN
- **CVSS Score:** 0.17
- **CWE:** N/A
- **Published:** Jun 11, 2002
- **Last Modified:** Mar 16, 2026

## Description

Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://www.securityfocus.com/bid/4501)
- [CNA](http://www.iss.net/security_center/static/8834.php)
- [CNA](http://archives.neohapsis.com/archives/bugtraq/2002-04/0140.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 4.35%
- **EPSS Percentile:** 88.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._