# CVE-2002-0647

## Summary

- **CVE ID:** CVE-2002-0647
- **Severity:** UNKNOWN
- **CVSS Score:** 0.62
- **CWE:** N/A
- **Published:** Apr 2, 2003
- **Last Modified:** Mar 16, 2026

## Description

Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-047)
- [CNA](http://www.securityfocus.com/bid/5558)
- [CNA](http://www.iss.net/security_center/static/9935.php)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 15.52%
- **EPSS Percentile:** 94.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._