CVE-2003-0400

Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.

Scoring

CVSS base score
0.2
EPSS probability
5.11%
Published
2003-06-11
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs