LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2002-0542

CVE-2002-0542

CVSS 7.2 · HIGH

Summary

mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.

CVSS 2.0 breakdown

Base score7.2 (HIGH)
VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Attack vectorLOCAL
Attack complexityLOW
ConfidentialityCOMPLETE
IntegrityCOMPLETE
AvailabilityCOMPLETE

Affected products

Openbsd openbsd
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-16. Always verify against the vendor advisory before acting.

Scroll to Top