CVE-2003-0899
critical · 9.8Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences.
9.8
CVSS
22.2%
EPSS (exploit prob.)
98th
EPSS percentile
2003-11-03
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-131
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| acme | thttpd | >= 2.21, < 2.23 |
| acme | thttpd | 2.23 |
| acme | thttpd | 2.23 |
Check a specific version with /api/v1/cve/match.
References
- http://marc.info/?l=bugtraq&m=106729188224252&w=2
- http://secunia.com/advisories/10092
- http://www.osvdb.org/2729
- http://www.securityfocus.com/bid/8906
- http://www.texonet.com/advisories/TEXONET-20030908.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13530
- https://www.debian.org/security/2003/dsa-396
- http://marc.info/?l=bugtraq&m=106729188224252&w=2
- http://secunia.com/advisories/10092
- http://www.osvdb.org/2729
- http://www.securityfocus.com/bid/8906
- http://www.texonet.com/advisories/TEXONET-20030908.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13530
- https://www.debian.org/security/2003/dsa-396
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2003-0899