17 Linux Kernel CVEs in 2003

Full year · Source: NIST NVD

2002 2004

In 2003, 17 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 0 were rated Critical, 5 High severity . Compared to 2002's 12 CVEs, 2003 represented an increase of 42% year-on-year. December was the most active month, with 6 CVEs published.

17
Total CVEs
0
Critical
5
High
8
Medium
4
Low
0
KEV Exploited

Monthly CVE Breakdown — 2003

CVEs published per month with severity breakdown

Monthly highlight

December (6) was the most active month in 2003. Together the top months account for a significant share of 2003's 17 total CVEs. February (1) had the lowest volume.

Critical
High
Medium
Low
Source: NIST NVD API.

Severity Distribution — 2003

Breakdown across 17 CVEs

Critical 0%
High 29%
Medium 47%
Low 24%
Severity breakdown

47% Medium · 29% High · 0% Critical.

Percentages rounded to nearest integer.

Monthly Counts — 2003

CVE counts by month and severity

Monthly highlight

December was the most active month with 6 CVEs — 35% of 2003's total. February (1) had the lowest volume.

Month Total Critical High Medium Low Share of year
February 1 0 0 0 1
6%
March 1 0 1 0 0
6%
June 4 0 1 2 1
24%
July 1 0 0 1 0
6%
August 4 0 0 4 0
24%
December 6 0 3 1 2
35%
Total 17 0 5 8 4
Click any month to view all CVEs published that month.

All CVEs — 2003

17 CVEs

All (17) Critical (0) High (5) Medium (8) Low (4)
CVE ID Package Severity CVSS Published Description
CVE-2003-0959 linux High 10.0 2003-12-31 Multiple integer overflows in the 32bit emulation for AMD64 architectures in Linux 2.4 kernel before 2.4.21 allows atta…
CVE-2003-0248 linux High 10.0 2003-06-16 The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.
CVE-2003-1161 linux High 7.2 2003-12-31 exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could a…
CVE-2003-0961 linux High 7.2 2003-12-15 Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users t…
CVE-2003-0127 linux High 7.2 2003-03-31 The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root …
CVE-2003-1288 linux Medium 5.0 2003-12-31 Multiple race conditions in Linux-VServer 1.22 with Linux kernel 2.4.23 and SMP allow local users to cause a denial of …
CVE-2003-0467 linux Medium 5.0 2003-08-27 Unknown vulnerability in ip_nat_sack_adjust of Netfilter in Linux kernels 2.4.20, and some 2.5.x, when CONFIG_IP_NF_NAT…
CVE-2003-0619 linux Medium 5.0 2003-08-27 Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers t…
CVE-2003-0465 linux Medium 5.0 2003-08-18 The kernel strncpy function in Linux 2.4 and 2.5 does not %NUL pad the buffer on architectures other than x86, as oppos…
CVE-2003-0418 linux Medium 5.0 2003-07-24 The Linux 2.0 kernel IP stack does not properly calculate the size of an ICMP citation, which causes it to include port…

2003 Linux Kernel CVE Highlights

  • Volume without critical severity

    Despite high CVE volume, 2003 produced only 0 Critical-rated vulnerabilities. 47% of 2003 CVEs are Medium severity. This means the surge in raw numbers does not represent a proportional surge in high-severity risk.

  • Monthly variation

    CVE publication in 2003 was uneven across months. December was the most active with 6 CVEs. February (1) had the lowest volume. Monthly spikes typically correspond to coordinated batches of backfilled CVEs being processed at once.

Frequently Asked Questions

How many Linux kernel CVEs were published in 2003?

17 Linux kernel CVEs were published in 2003, sourced from the NIST National Vulnerability Database. 0 were rated Critical, 5 High severity .

Which month had the most Linux kernel CVEs in 2003?

December 2003 had the most Linux kernel CVEs of any month in 2003, with 6 published — 35% of all 2003 CVEs. View December 2003 CVEs →

Why were there so many Linux kernel CVEs in 2003?

The volume of Linux kernel CVEs in 2003 reflects the kernel project's expanded use of its own CVE Numbering Authority (CNA), which began systematically publishing CVEs for a broader range of subsystem-level bugs — including many previously unreported or patched without a CVE assignment. This explains why volume surged while critical severity counts remained very low.

How does 2003 compare to previous years for Linux kernel CVEs?

2003 had 17 CVEs — increase of 42% compared to 2002's 12 . View the full year-by-year breakdown →

2002 statistics All-time stats 2004 statistics