Vulnerability Details CVE-2003-0400
Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.024
EPSS Ranking 84.5%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2003-0400
-
cpe:2.3:a:vignette:content_suite:6.0
-
cpe:2.3:a:vignette:storyserver:4.0
-
cpe:2.3:a:vignette:storyserver:4.1
-
cpe:2.3:a:vignette:storyserver:4.2
-
cpe:2.3:a:vignette:storyserver:5.0
-
cpe:2.3:a:vignette:vignette:5.0