SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

17,157 results · page 324 of 344

CVESummaryPriorityPublished
CVE-2003-1337Heap-based buffer overflow in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.HIGH 7.5EPSS 12.3%31 December 2003
CVE-2003-1336Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.EXPLOIT ×2HIGH 9.3EPSS 35.7%31 December 2003
CVE-2003-1303Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a…MEDIUM 5.0EPSS 12.1%31 December 2003
CVE-2003-1275Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript function that uses the object.innerHTML function to recursively call that function.EXPLOITMEDIUM 5.0EPSS 16.7%31 December 2003
CVE-2003-1236Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog.EXPLOITHIGH 10.0EPSS 15.2%31 December 2003
CVE-2003-1228Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via an HTTP request with a…EXPLOITHIGH 7.5EPSS 14.1%31 December 2003
CVE-2003-1177Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP…EXPLOITHIGH 7.5EPSS 12.9%31 December 2003
CVE-2003-1172Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a ..EXPLOITMEDIUM 5.0EPSS 30.8%31 December 2003
CVE-2003-1123Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.EXPLOITHIGH 7.5EPSS 11.1%31 December 2003
CVE-2003-1118Buffer overflow in the SETI@home client 3.03 and other versions allows remote attackers to cause a denial of service (client crash) and execute arbitrary code via a spoofed server response containing a long string followed by a \n (newline) character.EXPLOITHIGH 7.5EPSS 18.2%31 December 2003
CVE-2003-1105Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service (browser or Outlook Express crash) via HTML with certain input tags that are not properly rendered.LOW 2.6EPSS 17.7%31 December 2003
CVE-2003-1096The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute force password guessing attacks.EXPLOITHIGH 10.0EPSS 10.5%31 December 2003
CVE-2003-1083Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request.EXPLOIT ×2HIGH 10.0EPSS 21.1%31 December 2003
CVE-2003-1200Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbitrary code via a long From parameter to Form2Raw.cgi.EXPLOIT ×3HIGH 7.5EPSS 65.1%29 December 2003
CVE-2003-0962Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.HIGH 7.5EPSS 21.2%15 December 2003
CVE-2003-0824Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain…MEDIUM 5.0EPSS 34.6%15 December 2003
CVE-2003-0822Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.EXPLOIT ×2HIGH 7.5EPSS 81.3%15 December 2003
CVE-2003-0821Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.HIGH 7.5EPSS 19.0%15 December 2003
CVE-2003-0820Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.HIGH 7.5EPSS 25.7%15 December 2003
CVE-2003-0812Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated…EXPLOIT ×4HIGH 7.5EPSS 81.0%15 December 2003
CVE-2003-0886Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.EXPLOITHIGH 10.0EPSS 12.7%1 December 2003
CVE-2003-0896The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that…EXPLOITHIGH 7.5EPSS 14.3%17 November 2003
CVE-2003-0870Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped characters in the server name.EXPLOITHIGH 7.5EPSS 15.4%17 November 2003
CVE-2003-0866The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.EXPLOITMEDIUM 5.0EPSS 34.8%17 November 2003
CVE-2003-0865Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request.EXPLOITHIGH 7.5EPSS 14.5%17 November 2003
CVE-2003-0853An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited via applications that use ls, such as wu-ftpd.EXPLOITMEDIUM 5.0EPSS 11.1%17 November 2003
CVE-2003-0849Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the…EXPLOIT ×3HIGH 7.5EPSS 10.9%17 November 2003
CVE-2003-0845Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL…EXPLOITHIGH 7.5EPSS 15.4%17 November 2003
CVE-2003-0839Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via ..MEDIUM 5.0EPSS 13.5%17 November 2003
CVE-2003-0838Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats…EXPLOITHIGH 7.5EPSS 37.6%17 November 2003
CVE-2003-0831ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a buffer overflow using certain files.EXPLOIT ×3HIGH 9.0EPSS 58.4%17 November 2003
CVE-2003-0813A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one…MEDIUM 5.1EPSS 17.0%17 November 2003
CVE-2003-0809Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.EXPLOITHIGH 7.5EPSS 27.3%17 November 2003
CVE-2003-0717The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.EXPLOIT ×4HIGH 7.5EPSS 61.0%17 November 2003
CVE-2003-0714The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a…EXPLOIT ×2HIGH 7.5EPSS 77.6%17 November 2003
CVE-2003-0712Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.MEDIUM 4.3EPSS 19.9%17 November 2003
CVE-2003-0711Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.HIGH 7.5EPSS 37.4%17 November 2003
CVE-2003-0662Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.HIGH 9.3EPSS 38.0%17 November 2003
CVE-2003-0660The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers to execute arbitrary code without user approval.HIGH 7.5EPSS 24.5%17 November 2003
CVE-2003-0659Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.EXPLOIT ×2HIGH 7.2EPSS 43.0%17 November 2003
CVE-2003-0545Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.CRITICAL 9.8EPSS 87.5%17 November 2003
CVE-2003-0543Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.EXPLOITMEDIUM 5.0EPSS 27.4%17 November 2003
CVE-2003-1141Buffer overflow in NIPrint 4.10 allows remote attackers to execute arbitrary code via a long string to TCP port 515.EXPLOITHIGH 7.5EPSS 68.3%4 November 2003
CVE-2003-1192Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.EXPLOIT ×3HIGH 10.0EPSS 69.2%3 November 2003
CVE-2003-0899Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;"…EXPLOIT ×2CRITICAL 9.8EPSS 22.2%3 November 2003
CVE-2003-0789mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.HIGH 10.0EPSS 12.4%3 November 2003
CVE-2003-0542Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9…HIGH 7.2EPSS 30.4%3 November 2003
CVE-2003-0729Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.EXPLOITHIGH 7.5EPSS 10.4%20 October 2003
CVE-2003-0727Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.EXPLOIT ×6LOW 2.1EPSS 68.4%20 October 2003
CVE-2003-0725Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.EXPLOITHIGH 7.5EPSS 48.6%20 October 2003

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.