# CVE-2003-0787

## Summary

- **CVE ID:** CVE-2003-0787
- **Severity:** UNKNOWN
- **CVSS Score:** 0.02
- **CWE:** N/A
- **Published:** Sep 25, 2003
- **Last Modified:** Mar 16, 2026

## Description

The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://www.openssh.com/txt/sshpam.adv)
- [CNA](http://www.securityfocus.com/bid/8677)
- [CNA](http://www.kb.cert.org/vuls/id/209807)
- [CNA](http://www.securityfocus.com/archive/1/338617)
- [CNA](http://www.securityfocus.com/archive/1/338616)
- [CNA](http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.46%
- **EPSS Percentile:** 63.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._