Back

CVE-2003-0245

Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.

Published: Jun 9, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (9)

Vendor Product Version
apache http_server 2.0.37
apache http_server 2.0.38
apache http_server 2.0.39
apache http_server 2.0.40
apache http_server 2.0.41
apache http_server 2.0.42
apache http_server 2.0.43
apache http_server 2.0.44
apache http_server 2.0.45

GitHub Security Advisory GHSA-q57q-7777-f6xg

Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 62.36%

Top 1% most likely to be exploited

Threat Score 38.7 / 100

Data Sources

NVD EPSS GitHub