Vulnerability
CVE-2003-0899
CRITICAL 9.8
public exploit
CVE-2003-0899 is a critical-severity vulnerability (CVSS v3.1 9.8). As of 2026-10-09, 78 hosts in our data show software it affects on an open service in 8 countries.
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences.
- Published
- 2003-11-03
- Last modified
- 2026-06-16
- CVSS score
- 9.8 CVSS v3.1
- CVSS vector (v3.1)
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploit likelihood (EPSS)
- 22.2% in the next 30 days (higher than 98% of CVEs)
Exposure in our data
78 hosts
Hosts whose banner shows an affected software version on a service open at their latest check.
Not counted: 1 host with this CVE only from an older observation.
6 more hosts had it earlier (the software version has since changed or the service is gone).
Counted 2026-10-09 08:20 UTC
By country
| France FR | 65 |
| Netherlands NL | 5 |
| Switzerland CH | 2 |
| Thailand TH | 2 |
| Germany DE | 1 |
| Hong Kong HK | 1 |
| Portugal PT | 1 |
| United States US | 1 |
Affected software seen
| thttpd 2.22beta4 | 70 |
| thttpd 2.23beta1 | 8 |