CVE-2003-0225
The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 38.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 38.46% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/internet information server · microsoft/internet information services
- Source
- cve@mitre.org
References
- http://marc.info/?l=ntbugtraq&m=105110606122772&w=2
- http://www.aqtronix.com/Advisories/AQ-2003-01.txt
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A373
- http://marc.info/?l=ntbugtraq&m=105110606122772&w=2
- http://www.aqtronix.com/Advisories/AQ-2003-01.txt
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-018
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A373
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.