Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 327 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2003-0161 | The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a… | EXPLOIT ×2 ✓HIGH 10.0EPSS 38.8% | 2 April 2003 |
| CVE-2003-0083 | Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related… | MEDIUM 5.0EPSS 17.4% | 2 April 2003 |
| CVE-2002-1561 | The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference. | EXPLOIT ×4 ✓MEDIUM 5.0EPSS 37.7% | 2 April 2003 |
| CVE-2002-1522 | Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long USER argument. | EXPLOIT ×3 ✓MEDIUM 5.0EPSS 13.6% | 2 April 2003 |
| CVE-2002-1496 | Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a negative value in the Content-Length HTTP header. | EXPLOIT ✓HIGH 7.5EPSS 22.5% | 2 April 2003 |
| CVE-2002-1489 | Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name. | EXPLOIT ✓HIGH 7.5EPSS 10.6% | 2 April 2003 |
| CVE-2002-1487 | The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 206, (2) 211, (3) 213, (4) 214, (5) 215, (6) 217, (7) 218, (8) 243, (9) 302, (10) 317, (11) 324, (12)… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 13.6% | 2 April 2003 |
| CVE-2003-0109 | Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0. | EXPLOIT ×9 ✓HIGH 7.5EPSS 85.7% | 31 March 2003 |
| CVE-2003-0085 | Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code. | EXPLOIT ×3 ✓HIGH 10.0EPSS 87.9% | 31 March 2003 |
| CVE-2002-1560 | index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter to true. | EXPLOIT ✓HIGH 10.0EPSS 10.3% | 31 March 2003 |
| CVE-2002-1549 | Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. | EXPLOIT ×3 ✓HIGH 7.5EPSS 11.2% | 31 March 2003 |
| CVE-2002-1542 | SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow. | EXPLOIT ✓MEDIUM 5.0EPSS 13.2% | 31 March 2003 |
| CVE-2003-0028 | Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via… | HIGH 7.5EPSS 15.0% | 25 March 2003 |
| CVE-2003-0150 | MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by… | EXPLOIT ✓HIGH 9.0EPSS 44.8% | 24 March 2003 |
| CVE-2003-0130 | The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded… | EXPLOIT ✓MEDIUM 5.0EPSS 10.3% | 24 March 2003 |
| CVE-2003-0129 | Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times. | EXPLOIT ✓MEDIUM 5.0EPSS 11.6% | 24 March 2003 |
| CVE-2003-0128 | The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly… | EXPLOIT ✓MEDIUM 5.0EPSS 16.5% | 24 March 2003 |
| CVE-2003-0011 | Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of… | MEDIUM 5.0EPSS 13.3% | 24 March 2003 |
| CVE-2003-0010 | Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large… | HIGH 7.5EPSS 23.9% | 24 March 2003 |
| CVE-2003-0125 | Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value. | EXPLOIT ✓MEDIUM 5.0EPSS 10.8% | 18 March 2003 |
| CVE-2003-0122 | Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of… | MEDIUM 5.0EPSS 10.1% | 18 March 2003 |
| CVE-2003-0020 | Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences. | MEDIUM 5.0EPSS 16.5% | 18 March 2003 |
| CVE-2003-0108 | isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop. | EXPLOIT ✓MEDIUM 5.0EPSS 11.3% | 7 March 2003 |
| CVE-2003-0107 | Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code. | EXPLOIT ×2 ✓HIGH 7.5EPSS 26.0% | 7 March 2003 |
| CVE-2003-0050 | parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters. | EXPLOIT ✓HIGH 7.5EPSS 68.9% | 7 March 2003 |
| CVE-2003-0033 | Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets. | HIGH 10.0EPSS 11.9% | 7 March 2003 |
| CVE-2003-0009 | Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 16.5% | 7 March 2003 |
| CVE-2002-1337 | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c. | EXPLOIT ×3 ✓HIGH 10.0EPSS 72.6% | 7 March 2003 |
| CVE-2003-0101 | miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a… | EXPLOIT ✓HIGH 10.0EPSS 15.5% | 3 March 2003 |
| CVE-2003-0096 | Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the… | HIGH 9.0EPSS 15.9% | 3 March 2003 |
| CVE-2003-0095 | Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own… | HIGH 10.0EPSS 13.1% | 3 March 2003 |
| CVE-2003-0078 | ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch… | EXPLOIT ✓MEDIUM 5.0EPSS 13.7% | 3 March 2003 |
| CVE-2002-0842 | Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway messages (e.g. | HIGH 7.5EPSS 14.6% | 3 March 2003 |
| CVE-2003-1328 | The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security… | EXPLOIT ✓HIGH 7.5EPSS 38.9% | 19 February 2003 |
| CVE-2003-1326 | Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box." | HIGH 7.5EPSS 16.3% | 19 February 2003 |
| CVE-2003-0042 | Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character. | EXPLOIT ✓MEDIUM 5.0EPSS 46.0% | 7 February 2003 |
| CVE-2003-0027 | Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure. | MEDIUM 5.0EPSS 25.7% | 7 February 2003 |
| CVE-2003-0016 | Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names. | HIGH 7.5EPSS 17.8% | 7 February 2003 |
| CVE-2003-0015 | Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and… | EXPLOIT ✓HIGH 7.5EPSS 23.9% | 7 February 2003 |
| CVE-2003-0003 | Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter… | EXPLOIT ×2 ✓HIGH 7.5EPSS 43.4% | 7 February 2003 |
| CVE-2003-0002 | Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 23.3% | 7 February 2003 |
| CVE-2003-1090 | Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title. | EXPLOIT ✓HIGH 10.0EPSS 11.6% | 6 February 2003 |
| CVE-2003-0026 | Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long… | HIGH 7.5EPSS 18.9% | 17 January 2003 |
| CVE-2003-0025 | Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using… | HIGH 7.5EPSS 28.0% | 17 January 2003 |
| CVE-2003-0001 | Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak. | EXPLOIT ×3 ✓MEDIUM 5.0EPSS 70.2% | 17 January 2003 |
| CVE-2002-2380 | NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented usernames and passwords from network traffic. | MEDIUM 6.4EPSS 10.9% | 31 December 2002 |
| CVE-2002-2328 | Active Directory in Windows 2000, when supporting Kerberos V authentication and GSSAPI, allows remote attackers to cause a denial of service (hang) via an LDAP client that sets the page length to zero during a large request. | HIGH 7.1EPSS 16.6% | 31 December 2002 |
| CVE-2002-2281 | JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java commands via an applet that uses a jump call, which is not correctly compiled by the JIT compiler. | EXPLOIT ✓HIGH 10.0EPSS 10.2% | 31 December 2002 |
| CVE-2002-2268 | Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL. | EXPLOIT ×2 ✓HIGH 9.4EPSS 51.7% | 31 December 2002 |
| CVE-2002-2226 | Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument. | EXPLOIT ×2 ✓HIGH 7.5EPSS 63.5% | 31 December 2002 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.