Back

CVE-2003-0015

Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.

Published: Feb 7, 2003 Modified: Jun 16, 2026
CWE-415

CVSS Metrics

Affected Products (13)

Vendor Product Version
freebsd freebsd 4.4
freebsd freebsd 4.5
freebsd freebsd 4.6
freebsd freebsd 4.7
freebsd freebsd 5.0
cvs cvs 1.10.7
cvs cvs 1.10.8
cvs cvs 1.11
cvs cvs 1.11.1
cvs cvs 1.11.1p1
cvs cvs 1.11.2
cvs cvs 1.11.3
cvs cvs 1.11.4

GitHub Security Advisory GHSA-jj52-xc36-fq8r

Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 23.87%

Top 2% most likely to be exploited

Threat Score 37.2 / 100

Data Sources

NVD EPSS GitHub