peter bassill · operator
$ cve CVE-2003-0107 JSON

CVE-2003-0107 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 26% (pctl 98)

Patch early

A public exploit exists.

Description

Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS25.99% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2003-03-07
Last modified2026-06-16

Affected (1)

VendorProduct
zlibzlib

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD