VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 17 hours ago
Reset
More filters (3)
Columns
Published from 2003-01-01Published to 2003-12-31Has a public PoC
Overview 6 matches, all in RASP scope, all public PoC · 1 protected · 0 KEV · 0 CISA SSVC · 0 EPSS ≥ 0.5 · 0 disputed
6matches, all in RASP scope, all public PoC 1protected16.7% 0KEV0.0% 0CISA SSVC0.0% 0EPSS ≥ 0.50.0% 0disputed0.0%
Critical 0 0.0% High 2 33.3% Medium 4 66.7% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 1 16.7% Rule in development 0 0.0% Mitigation candidate 5 83.3% No exploit published 0 0.0% No fix identified 0 0.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 1 16.7% not blocked 5 83.3% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 6 100.0% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 0 0.0%
split by peak 2 / month
Unknown: 0None: 0Low: 0Medium: 4High: 2Critical: 0 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 0No exploit published: 0Mitigation candidate: 5Rule in development: 0Protected by RASP: 1 unrecorded: 0not established: 0not blocked: 5blocked by ARMR today: 1 No public exploit: 0Forecast only: 0Proof of concept only: 0Working exploit published: 6Exploited in the wild: 0 February 2003: 1 CVE March 2003: 1 CVE April 2003: 0 CVEs May 2003: 0 CVEs June 2003: 0 CVEs July 2003: 0 CVEs August 2003: 0 CVEs September 2003: 0 CVEs October 2003: 1 CVE November 2003: 2 CVEs December 2003: 1 CVE
Feb 03Mar 03Apr 03May 03Jun 03Jul 03Aug 03Sep 03Oct 03Nov 03Dec 03
6 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2003-1123 High 2003-12-31 Mitigation candidate Working exploit published Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.
CVE-2003-0896 High 2003-11-17 Mitigation candidate Working exploit published The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAccess method.
CVE-2003-0866 Medium 2003-11-17 Mitigation candidate Working exploit published The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.
CVE-2002-1567 Medium 2003-10-06 Mitigation candidate Working exploit published Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
CVE-2002-1533 Medium 2003-03-31 Mitigation candidate Working exploit published Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).
CVE-2003-0042 Medium 2003-02-07 Protected by RASP Working exploit published Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.