Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 325 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2003-0686 | Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code. | EXPLOIT ✓HIGH 7.5EPSS 27.0% | 20 October 2003 |
| CVE-2003-0666 | Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters in a Corel WordPerfect file. | EXPLOIT ×2 ✓HIGH 7.5EPSS 21.9% | 20 October 2003 |
| CVE-2003-0665 | Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control. | EXPLOIT ✓HIGH 7.5EPSS 30.1% | 20 October 2003 |
| CVE-2003-0661 | The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information. | MEDIUM 5.0EPSS 25.2% | 20 October 2003 |
| CVE-2003-0347 | Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter. | EXPLOIT ✓HIGH 10.0EPSS 54.9% | 20 October 2003 |
| CVE-2003-0826 | lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attackers to execute arbitrary code via a heap-based buffer… | EXPLOIT ×2 ✓HIGH 7.5EPSS 12.1% | 6 October 2003 |
| CVE-2003-0801 | Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script. | EXPLOIT ✓MEDIUM 4.3EPSS 12.2% | 6 October 2003 |
| CVE-2003-0694 | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | HIGH 10.0EPSS 66.2% | 6 October 2003 |
| CVE-2003-0681 | A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences. | EXPLOIT ✓HIGH 7.5EPSS 22.4% | 6 October 2003 |
| CVE-2002-1567 | Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script. | EXPLOIT ✓MEDIUM 6.8EPSS 27.1% | 6 October 2003 |
| CVE-2003-0780 | Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field. | EXPLOIT ×2 ✓HIGH 9.0EPSS 78.4% | 22 September 2003 |
| CVE-2003-0772 | Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments. | EXPLOIT ✓HIGH 7.5EPSS 84.9% | 22 September 2003 |
| CVE-2003-0770 | FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement. | EXPLOIT ×2 ✓HIGH 7.5EPSS 11.1% | 22 September 2003 |
| CVE-2003-0768 | Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name. | MEDIUM 6.8EPSS 13.0% | 22 September 2003 |
| CVE-2003-0722 | The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets. | EXPLOIT ×2 ✓HIGH 10.0EPSS 88.8% | 22 September 2003 |
| CVE-2003-0693 | A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than… | HIGH 10.0EPSS 11.4% | 22 September 2003 |
| CVE-2003-0720 | Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type. | EXPLOIT ✓HIGH 7.5EPSS 12.9% | 17 September 2003 |
| CVE-2003-0715 | Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a… | HIGH 10.0EPSS 40.3% | 17 September 2003 |
| CVE-2003-0528 | Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than… | HIGH 10.0EPSS 41.0% | 17 September 2003 |
| CVE-2003-0701 | Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execute arbitrary code via the Type property of an Object tag, a variant of CVE-2003-0344. | EXPLOIT ✓HIGH 7.5EPSS 30.1% | 27 August 2003 |
| CVE-2003-0619 | Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call. | EXPLOIT ✓MEDIUM 5.0EPSS 10.9% | 27 August 2003 |
| CVE-2003-0605 | The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject… | EXPLOIT ×10 ✓HIGH 7.5EPSS 58.8% | 27 August 2003 |
| CVE-2003-0604 | Windows Media Player (WMP) 7 and 8, as running on Internet Explorer and possibly other Microsoft products that process HTML, allows remote attackers to bypass zone restrictions and access or execute arbitrary files via an IFRAME tag pointing to an ASF… | HIGH 7.5EPSS 13.0% | 27 August 2003 |
| CVE-2003-0562 | Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string. | EXPLOIT ✓MEDIUM 5.0EPSS 14.3% | 27 August 2003 |
| CVE-2003-0540 | The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 21.3% | 27 August 2003 |
| CVE-2003-0532 | Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a… | HIGH 7.5EPSS 23.0% | 27 August 2003 |
| CVE-2003-0531 | Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in the My Computer domain using the browser cache via crafted Content-Type and Content-Disposition headers, aka the "Browser Cache Script Execution in My… | HIGH 7.5EPSS 26.5% | 27 August 2003 |
| CVE-2003-0530 | Buffer overflow in the BR549.DLL ActiveX control for Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to execute arbitrary code. | HIGH 7.5EPSS 30.4% | 27 August 2003 |
| CVE-2003-0466 | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to… | EXPLOIT ×5 ✓CRITICAL 9.8EPSS 78.1% | 27 August 2003 |
| CVE-2003-0460 | The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service. | MEDIUM 5.0EPSS 13.4% | 27 August 2003 |
| CVE-2003-0353 | Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434. | HIGH 7.5EPSS 21.7% | 27 August 2003 |
| CVE-2003-0346 | Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which… | HIGH 7.5EPSS 32.7% | 27 August 2003 |
| CVE-2003-0231 | Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe. | EXPLOIT ✓MEDIUM 5.0EPSS 36.2% | 27 August 2003 |
| CVE-2003-0567 | Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full. | EXPLOIT ×3 ✓HIGH 7.8EPSS 16.6% | 18 August 2003 |
| CVE-2003-0558 | Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request. | EXPLOIT ×2 ✓HIGH 7.5EPSS 56.5% | 18 August 2003 |
| CVE-2003-0526 | Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed… | EXPLOIT ✓MEDIUM 6.8EPSS 22.5% | 18 August 2003 |
| CVE-2003-0519 | Certain versions of Internet Explorer 5 and 6, in certain Windows environments, allow remote attackers to cause a denial of service (freeze) via a URL to C:\aux (MS-DOS device name) and possibly other devices. | MEDIUM 5.0EPSS 10.8% | 18 August 2003 |
| CVE-2003-0352 | Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms. | EXPLOIT ×3 ✓HIGH 7.5EPSS 98.5% | 18 August 2003 |
| CVE-2003-0345 | Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required. | HIGH 7.5EPSS 34.6% | 18 August 2003 |
| CVE-2003-0252 | Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain… | CRITICAL 9.8EPSS 15.8% | 18 August 2003 |
| CVE-2001-1410 | Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow attackers to simulate a victim's display and conduct unauthorized activities or steal sensitive data… | EXPLOIT ✓MEDIUM 5.0EPSS 50.5% | 18 August 2003 |
| CVE-2003-0507 | Stack-based buffer overflow in Active Directory in Windows 2000 before SP4 allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via an LDAP version 3 search request with a large number of (1) "AND," (2) "OR,"… | HIGH 7.5EPSS 26.8% | 7 August 2003 |
| CVE-2003-0506 | Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation. | MEDIUM 5.0EPSS 10.8% | 7 August 2003 |
| CVE-2003-0505 | Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request. | MEDIUM 5.0EPSS 13.5% | 7 August 2003 |
| CVE-2003-0500 | SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name. | EXPLOIT ✓HIGH 10.0EPSS 18.3% | 7 August 2003 |
| CVE-2003-0487 | Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parameter in the do_subscribe module, (2) a long folder parameter in the… | EXPLOIT ×5 ✓HIGH 7.5EPSS 11.4% | 7 August 2003 |
| CVE-2003-0478 | Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote… | EXPLOIT ✓HIGH 10.0EPSS 12.3% | 7 August 2003 |
| CVE-2003-0471 | Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a long USER argument. | EXPLOIT ×4 ✓HIGH 7.5EPSS 61.0% | 7 August 2003 |
| CVE-2003-0469 | Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer… | EXPLOIT ✓HIGH 7.5EPSS 44.6% | 7 August 2003 |
| CVE-2003-0447 | The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument to shdocvw.dll that causes a "javascript:" link to be generated. | EXPLOIT ✓MEDIUM 5.1EPSS 13.7% | 24 July 2003 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.