CVE-2003-1331
Status: ModifiedMedium (4)—
Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.
CVSS
- Version: 2.0
- Vector: AV:N/AC:H/Au:N/C:N/I:P/A:P
- Base score: 4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.28%
- Percentile among all scored CVEs: 88
- Score date: 10/11/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/1303.html
- http://bugs.mysql.com/bug.php?id=564
- http://www.securityfocus.com/bid/7887
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12337
- http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/1303.html
- http://bugs.mysql.com/bug.php?id=564
- http://www.securityfocus.com/bid/7887
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12337
Raw JSON (NVD)
Show
{
"id": "CVE-2003-1331",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "HIGH",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2003-12-31T05:00:00.000",
"references": [
{
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/1303.html",
"source": "cve@mitre.org"
},
{
"url": "http://bugs.mysql.com/bug.php?id=564",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/7887",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/12337",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/1303.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://bugs.mysql.com/bug.php?id=564",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/7887",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/12337",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453."
}
],
"lastModified": "2026-06-16T22:03:56.810",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:mysql:*:gamma:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B90917FD-7681-4551-9FB1-214348C6A2D6",
"versionEndIncluding": "4.0.9"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "Red Hat does not consider this issue to be a security vulnerability since no trust boundary is crossed. The user must voluntarily interact with the attack mechanism to exploit this flaw, with the result being the ability to run code as themselves.\n",
"lastModified": "2007-06-29T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}