CVE-2003-0616
Last modified
CVE-2003-0616 is a vulnerability of currently unknown severity. Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.. EPSS estimates a 3.04% chance of exploitation in the next 30 days.
Description
Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Epolicy Orchestrator | 2.0 |
| Mcafee | Epolicy Orchestrator | 2.5 |
| Mcafee | Epolicy Orchestrator | 2.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0616?
How severe is CVE-2003-0616?
How do I fix CVE-2003-0616?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-0610Directory traversal vulnerability in ePO agent for McAfee eP…
- CVE-2003-0611Multiple buffer overflows in xtokkaetama 1.0 allow local use…
- CVE-2003-0612Multiple buffer overflows in main.c for Crafty 19.3 allow lo…
- CVE-2003-0613Buffer overflow in zblast-svgalib of zblast 1.2.1 and earlie…
- CVE-2003-0614Cross-site scripting (XSS) vulnerability in search.php of Ga…
- CVE-2003-0615Cross-site scripting (XSS) vulnerability in start_form() of …
- CVE-2003-0617mindi 0.58 and earlier does not properly create temporary fi…
- CVE-2003-0618Multiple vulnerabilities in suidperl 5.6.1 and earlier allow…
- CVE-2003-0619Integer signedness error in the decode_fh function of nfs3xd…
- CVE-2003-0620Multiple buffer overflows in man-db 2.4.1 and earlier, when …
- CVE-2003-0621The Administration Console for BEA Tuxedo 8.1 and earlier al…
- CVE-2003-0622The Administration Console for BEA Tuxedo 8.1 and earlier al…
Are you affected by CVE-2003-0616?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
