Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2003-0400

Опубликовано: 30 июн. 2003
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vignette:content_suite:6.0:*:*:*:*:*:*:*
cpe:2.3:a:vignette:storyserver:4.0:*:*:*:*:*:*:*
cpe:2.3:a:vignette:storyserver:4.1:*:*:*:*:*:*:*
cpe:2.3:a:vignette:storyserver:4.2:*:*:*:*:*:*:*
cpe:2.3:a:vignette:storyserver:5.0:*:*:*:*:*:*:*
cpe:2.3:a:vignette:vignette:5.0:*:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.05107
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.

EPSS

Процентиль: 90%
0.05107
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other