VULNERABILITY INTELLIGENCE

CVE-2003-0899

CVSS score9.8 CRITICAL
EPSS probability22.19%
CISA KEVNot currently listed
Published2003-11-03
Last modified2026-06-16
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.

Weakness classification

  • CWE-131: Incorrect Calculation of Buffer Size

Primary references