Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2003-0010

33
FAUCET Score

CVE-2003-0010 describes an integer overflow vulnerability in the JsArrayFunctionHeapSort function within the Windows Script Engine for JScript (JScript.dll), affecting various Windows operating systems including 2000, 98, ME, NT, and XP. This flaw allows remote attackers to execute arbitrary code by crafting a malicious web page or HTML email that exploits a large array index value, leading to a heap-based buffer overflow. The vulnerability carries a CVSS score of 7.5, indicating a high severity with a network attack vector, low complexity, and potential for partial impact on confidentiality, integrity, and availability. While the EPSS score suggests a moderate likelihood of exploitation, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage for this older vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2000_terminal_services:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
23.89%
Probability of exploitation in next 30 days
EPSS Percentile
97.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.2389 is in the 96th percentile among its peer group of 51,466 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

archives.neohapsis.com / archives/vulnwatch/2003-q1/0139.html
labs.idefense.com / intelligence/vulnerabilities/display.php
marc.info
docs.microsoft.com / en-us/security-updates/securitybulletins/2003/ms03-008
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A134
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A200
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A794
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A795
securityfocus.com / bid/7146
PatchVendor Advisory