CVE-2003-0026

Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.

Published: 2003-01-17 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2003-0026 is rated High Risk (68.9/100): CVSS High severity, with high exploitation likelihood (EPSS 18.85%, 97th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +6.44% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2003-0026

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 12.42% 18.85% +6.44%
2 2025-03-30 8.14% 12.42% +4.28%
3 2025-03-29 8.14%

Full EPSS history (8 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2003-0026

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.5 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 6.4 [email protected]

Weakness enumeration for CVE-2003-0026

OS Trackers for CVE-2003-0026

vendor priority summary link
redhat https://access.redhat.com/security/cve/CVE-2003-0026

Affected software / configurations for CVE-2003-0026

Vendor Product Version Raw CPE
isc dhcpd 3.0 cpe:2.3:a:isc:dhcpd:3.0:*:*:*:*:*:*:*
isc dhcpd 3.0.1 cpe:2.3:a:isc:dhcpd:3.0.1:rc1:*:*:*:*:*:*
isc dhcpd 3.0.1 cpe:2.3:a:isc:dhcpd:3.0.1:rc2:*:*:*:*:*:*
isc dhcpd 3.0.1 cpe:2.3:a:isc:dhcpd:3.0.1:rc3:*:*:*:*:*:*
isc dhcpd 3.0.1 cpe:2.3:a:isc:dhcpd:3.0.1:rc4:*:*:*:*:*:*
isc dhcpd 3.0.1 cpe:2.3:a:isc:dhcpd:3.0.1:rc5:*:*:*:*:*:*
isc dhcpd 3.0.1 cpe:2.3:a:isc:dhcpd:3.0.1:rc6:*:*:*:*:*:*
isc dhcpd 3.0.1 cpe:2.3:a:isc:dhcpd:3.0.1:rc7:*:*:*:*:*:*
isc dhcpd 3.0.1 cpe:2.3:a:isc:dhcpd:3.0.1:rc8:*:*:*:*:*:*

References for CVE-2003-0026

URL Tags
http://archives.neohapsis.com/archives/bugtraq/2003-01/0250.html
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000562
http://www.cert.org/advisories/CA-2003-01.html Patch Third Party Advisory US Government Resource
http://www.ciac.org/ciac/bulletins/n-031.shtml
http://www.debian.org/security/2003/dsa-231 Patch Vendor Advisory
http://www.kb.cert.org/vuls/id/284857 Patch Third Party Advisory US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2003:007
http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.002.html
http://www.redhat.com/support/errata/RHSA-2003-011.html Patch Vendor Advisory
http://www.securityfocus.com/bid/6627
http://www.securitytracker.com/id?1005924
http://www.suse.com/de/security/2003_006_dhcp.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/11073
cvelogic Threat Intelligence