Vulnerability

CVE-2003-0899

CRITICAL 9.8 public exploit

CVE-2003-0899 is a critical-severity vulnerability (CVSS v3.1 9.8). As of 2026-10-09, 78 hosts in our data show software it affects on an open service in 8 countries.

Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.

Published
2003-11-03
Last modified
2026-06-16
CVSS score
9.8 CVSS v3.1
CVSS vector (v3.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploit likelihood (EPSS)
22.2% in the next 30 days (higher than 98% of CVEs)

Exposure in our data

78 hosts

Hosts whose banner shows an affected software version on a service open at their latest check.

Not counted: 1 host with this CVE only from an older observation.

6 more hosts had it earlier (the software version has since changed or the service is gone).

Counted 2026-10-09 08:20 UTC

By country

France FR65
Netherlands NL5
Switzerland CH2
Thailand TH2
Germany DE1
Hong Kong HK1
Portugal PT1
United States US1

Affected software seen

thttpd 2.22beta470
thttpd 2.23beta18