CVE-2003-0225

4 documents4 sources
Severity
5.0MEDIUM
EPSS
57.6%
top 1.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateApr 29

Description

The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

🔴Vulnerability Details

2
GHSA
GHSA-xh9p-h3qw-7x43: The ASP function Response2022-04-29
CVEList
CVE-2003-0225: The ASP function Response2003-05-30
CVE-2003-0225 (MEDIUM CVSS 5) | The ASP function Response.AddHeader | cvebase.io