Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,035 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 326 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2003-0446 | Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the… | EXPLOIT ✓MEDIUM 4.3EPSS 23.0% | 24 July 2003 |
| CVE-2003-0434 | Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink. | EXPLOIT ✓HIGH 7.5EPSS 40.9% | 24 July 2003 |
| CVE-2003-0349 | Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a… | EXPLOIT ×3 ✓HIGH 7.5EPSS 80.3% | 24 July 2003 |
| CVE-2003-0348 | A certain Microsoft Windows Media Player 9 Series ActiveX control allows remote attackers to view and manipulate the Media Library on the local system via HTML script. | MEDIUM 6.4EPSS 19.9% | 24 July 2003 |
| CVE-2003-0411 | Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension. | EXPLOIT ✓HIGH 7.5EPSS 25.1% | 30 June 2003 |
| CVE-2003-0407 | Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string. | EXPLOIT ×2 ✓HIGH 10.0EPSS 16.4% | 30 June 2003 |
| CVE-2003-0344 | Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page. | EXPLOIT ×3 ✓HIGH 7.5EPSS 81.3% | 16 June 2003 |
| CVE-2003-0282 | Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . | EXPLOIT ✓LOW 2.6EPSS 22.0% | 16 June 2003 |
| CVE-2003-0280 | Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands. | EXPLOIT ×2 ✓HIGH 10.0EPSS 14.7% | 16 June 2003 |
| CVE-2003-0276 | Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request with a large number of / characters. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 11.4% | 16 June 2003 |
| CVE-2003-0270 | The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing… | HIGH 7.6EPSS 11.0% | 16 June 2003 |
| CVE-2003-0195 | CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out. | EXPLOIT ✓MEDIUM 5.0EPSS 10.6% | 16 June 2003 |
| CVE-2003-0309 | Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple… | EXPLOIT ✓HIGH 7.5EPSS 50.0% | 9 June 2003 |
| CVE-2003-0245 | Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated… | EXPLOIT ✓MEDIUM 5.0EPSS 63.5% | 9 June 2003 |
| CVE-2003-0240 | The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash). | EXPLOIT ✓HIGH 10.0EPSS 29.5% | 9 June 2003 |
| CVE-2003-0227 | The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information… | EXPLOIT ✓MEDIUM 5.0EPSS 34.4% | 9 June 2003 |
| CVE-2003-0226 | Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 43.2% | 9 June 2003 |
| CVE-2003-0225 | The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory… | MEDIUM 5.0EPSS 38.5% | 9 June 2003 |
| CVE-2003-0224 | Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer… | HIGH 10.0EPSS 18.3% | 9 June 2003 |
| CVE-2003-0223 | Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message. | MEDIUM 6.8EPSS 17.3% | 9 June 2003 |
| CVE-2003-0189 | The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid… | MEDIUM 5.0EPSS 15.1% | 9 June 2003 |
| CVE-2002-1564 | Internet Explorer 5.5 and 6.0 allows remote attackers to steal potentially sensitive information from cookies via a cookie that contains script which is executed when a page is loaded, aka the "Script within Cookies Reading Cookies" vulnerability. | MEDIUM 5.0EPSS 11.7% | 9 June 2003 |
| CVE-2002-1456 | Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value. | EXPLOIT ✓HIGH 7.5EPSS 11.6% | 9 June 2003 |
| CVE-2003-0264 | Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO argument to slmail.exe, (2) a long XTRN argument to slmail.exe, (3) a long string to POPPASSWD, or (4) a long password to the POP3 server. | EXPLOIT ×4 ✓HIGH 7.5EPSS 71.5% | 27 May 2003 |
| CVE-2003-0263 | Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands. | EXPLOIT ×2 ✓HIGH 7.5EPSS 11.6% | 27 May 2003 |
| CVE-2003-0228 | Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes… | EXPLOIT ✓HIGH 7.5EPSS 46.3% | 27 May 2003 |
| CVE-2003-0233 | Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115. | HIGH 7.5EPSS 18.9% | 12 May 2003 |
| CVE-2003-0222 | Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter. | HIGH 9.0EPSS 11.0% | 12 May 2003 |
| CVE-2003-0220 | Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet. | EXPLOIT ×5 ✓HIGH 7.5EPSS 69.1% | 12 May 2003 |
| CVE-2003-0213 | ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow. | EXPLOIT ×5 ✓HIGH 7.5EPSS 70.9% | 12 May 2003 |
| CVE-2003-0190 | OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack. | EXPLOIT ×3 ✓MEDIUM 5.0EPSS 76.8% | 12 May 2003 |
| CVE-2003-0116 | Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and… | MEDIUM 5.0EPSS 25.2% | 12 May 2003 |
| CVE-2003-0115 | Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a… | HIGH 7.5EPSS 11.6% | 12 May 2003 |
| CVE-2003-0114 | The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files. | MEDIUM 5.0EPSS 14.6% | 12 May 2003 |
| CVE-2003-0113 | Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields. | EXPLOIT ✓HIGH 7.5EPSS 39.4% | 12 May 2003 |
| CVE-2003-0209 | Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow. | EXPLOIT ✓HIGH 10.0EPSS 38.6% | 5 May 2003 |
| CVE-2003-0201 | Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code. | EXPLOIT ×12 ✓HIGH 10.0EPSS 84.5% | 5 May 2003 |
| CVE-2003-0196 | Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201. | HIGH 10.0EPSS 22.8% | 5 May 2003 |
| CVE-2003-0111 | The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw… | EXPLOIT ✓HIGH 7.5EPSS 36.7% | 5 May 2003 |
| CVE-2003-0110 | The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed,… | MEDIUM 5.0EPSS 18.0% | 5 May 2003 |
| CVE-2002-1484 | DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces… | EXPLOIT ✓CRITICAL 9.8EPSS 13.7% | 22 April 2003 |
| CVE-2003-0132 | A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 86.7% | 11 April 2003 |
| CVE-2002-1437 | Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences. | MEDIUM 5.0EPSS 17.0% | 11 April 2003 |
| CVE-2002-1426 | HP ProCurve Switch 4000M C.07.23 allows remote attackers to cause a denial of service (crash) via an SNMP write request containing 85 characters, possibly triggering a buffer overflow. | EXPLOIT ✓HIGH 7.8EPSS 19.7% | 11 April 2003 |
| CVE-2002-1417 | Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to read arbitrary files via a URL containing a "..%5c" sequence (modified dot-dot),… | MEDIUM 5.0EPSS 16.6% | 11 April 2003 |
| CVE-2002-1412 | Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERY_BASEDIR variable that points to a directory or URL that contains a Trojan horse init.php script. | EXPLOIT ✓HIGH 7.5EPSS 39.5% | 11 April 2003 |
| CVE-2002-1143 | Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 53.6% | 11 April 2003 |
| CVE-2003-0178 | Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the… | HIGH 10.0EPSS 14.9% | 2 April 2003 |
| CVE-2003-0172 | Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument. | EXPLOIT ✓HIGH 7.5EPSS 19.0% | 2 April 2003 |
| CVE-2003-0166 | Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2)… | EXPLOIT ×3 ✓HIGH 7.5EPSS 14.1% | 2 April 2003 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.