# CVE-2002-1306

## Summary

- **CVE ID:** CVE-2002-1306
- **Severity:** UNKNOWN
- **CVSS Score:** 0.22
- **CWE:** N/A
- **Published:** Nov 21, 2002
- **Last Modified:** Mar 16, 2026

## Description

Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote attackers to execute arbitrary code via a certain "lan://" URL.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-080.php)
- [CNA](http://marc.info/?l=bugtraq&m=103728981029342&w=2)
- [CNA](http://marc.info/?l=bugtraq&m=103712329102632&w=2)
- [CNA](http://www.kde.org/info/security/advisory-20021111-2.txt)
- [CNA](http://www.iss.net/security_center/static/10597.php)
- [CNA](http://www.ciac.org/ciac/bulletins/n-020.shtml)
- [CNA](http://www.iss.net/security_center/static/10598.php)
- [CNA](http://www.debian.org/security/2002/dsa-214)
- [CNA](http://www.redhat.com/support/errata/RHSA-2002-220.html)
- [CNA](http://www.novell.com/linux/security/advisories/2002_042_kdenetwork.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 5.54%
- **EPSS Percentile:** 90.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._