← All CVEs

CVE-2003-0899

critical · 9.8

Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.

9.8
CVSS
22.2%
EPSS (exploit prob.)
98th
EPSS percentile
2003-11-03
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-131

Affected products

VendorProductAffected versions
acmethttpd>= 2.21, < 2.23
acmethttpd2.23
acmethttpd2.23

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2003-0899