In 2002, 12 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 0 were rated Critical, 2 High severity . Compared to 2001's 19 CVEs, 2002 represented a decrease of 37% year-on-year. December was the most active month, with 7 CVEs published.
Monthly CVE Breakdown — 2002
CVEs published per month with severity breakdown
December (7) was the most active month in 2002. Together the top months account for a significant share of 2002's 12 total CVEs. January (1) had the lowest volume.
Severity Distribution — 2002
Breakdown across 12 CVEs
17% Medium · 17% High · 0% Critical.
Monthly Counts — 2002
CVE counts by month and severity
December was the most active month with 7 CVEs — 58% of 2002's total. January (1) had the lowest volume.
| Month | Total | Critical | High | Medium | Low | Share of year |
|---|---|---|---|---|---|---|
| January | 1 | 0 | 0 | 1 | 0 |
8%
|
| July | 1 | 0 | 0 | 0 | 1 |
8%
|
| August | 3 | 0 | 0 | 1 | 2 |
25%
|
| December | 7 | 0 | 2 | 0 | 5 |
58%
|
| Total | 12 | 0 | 2 | 2 | 8 |
All CVEs — 2002
12 CVEs
| CVE ID | Package | Severity | CVSS | Published | Description | |
|---|---|---|---|---|---|---|
| CVE-2002-1572 | linux | High | 10.0 | 2002-12-31 | Signed integer overflow in the bttv_read function in the bttv driver (bttv-driver.c) in Linux kernel before 2.4.20 has … | |
| CVE-2002-1573 | linux | High | 10.0 | 2002-12-31 | Unspecified vulnerability in the pcilynx ieee1394 firewire driver (pcilynx.c) in Linux kernel before 2.4.20 has unknown… | |
| CVE-2002-0510 | linux | Medium | 5.0 | 2002-08-12 | The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, wh… | |
| CVE-2002-0046 | linux | Medium | 5.0 | 2002-01-31 | Linux kernel, and possibly other operating systems, allows remote attackers to read portions of memory via a series of … | |
| CVE-2002-0429 | linux | Low | 3.6 | 2002-08-12 | The iBCS routines in arch/i386/kernel/traps.c for Linux kernels 2.4.18 and earlier on x86 systems allow local users to … | |
| CVE-2002-1571 | linux | Low | 2.1 | 2002-12-31 | The linux 2.4 kernel before 2.4.19 assumes that the fninit instruction clears all registers, which could lead to an inf… | |
| CVE-2002-1963 | linux | Low | 2.1 | 2002-12-31 | Linux kernel 2.4.1 through 2.4.19 sets root's NR_RESERVED_FILES limit to 10 files, which allows local users to cause a … | |
| CVE-2002-2254 | linux | Low | 2.1 | 2002-12-31 | The experimental IP packet queuing feature in Netfilter / IPTables in Linux kernel 2.4 up to 2.4.19 and 2.5 up to 2.5.3… | |
| CVE-2002-1380 | linux | Low | 2.1 | 2002-12-23 | Linux kernel 2.2.x allows local users to cause a denial of service (crash) by using the mmap() function with a PROT_REA… | |
| CVE-2002-1319 | linux | Low | 2.1 | 2002-12-11 | The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of se… |
2002 Linux Kernel CVE Highlights
-
Volume without critical severity
Despite high CVE volume, 2002 produced only 0 Critical-rated vulnerabilities. 17% of 2002 CVEs are Medium severity. This means the surge in raw numbers does not represent a proportional surge in high-severity risk.
-
Monthly variation
CVE publication in 2002 was uneven across months. December was the most active with 7 CVEs. January (1) had the lowest volume. Monthly spikes typically correspond to coordinated batches of backfilled CVEs being processed at once.