← All CVEs

CVE-2003-0016

high · 7.5

Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.

7.5
CVSS
17.8%
EPSS (exploit prob.)
97th
EPSS percentile
2003-02-07
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
apachehttp_server2.0.36
apachehttp_server2.0.37
apachehttp_server2.0.38
apachehttp_server2.0.39
apachehttp_server2.0.40
apachehttp_server2.0.41
apachehttp_server2.0.42
apachehttp_server2.0.43

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2003-0016