← All CVEs

CVE-2003-0001

medium · 5

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.

5
CVSS
70.2%
EPSS (exploit prob.)
99th
EPSS percentile
2003-01-17
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
freebsdfreebsd4.2
freebsdfreebsd4.3
freebsdfreebsd4.4
freebsdfreebsd4.5
freebsdfreebsd4.6
freebsdfreebsd4.7
linuxlinux_kernel2.4.1
linuxlinux_kernel2.4.2
linuxlinux_kernel2.4.3
linuxlinux_kernel2.4.4
linuxlinux_kernel2.4.5
linuxlinux_kernel2.4.6
linuxlinux_kernel2.4.7
linuxlinux_kernel2.4.8
linuxlinux_kernel2.4.9
linuxlinux_kernel2.4.10
linuxlinux_kernel2.4.11
linuxlinux_kernel2.4.12
linuxlinux_kernel2.4.13
linuxlinux_kernel2.4.14
linuxlinux_kernel2.4.15
linuxlinux_kernel2.4.16
linuxlinux_kernel2.4.17
linuxlinux_kernel2.4.18
linuxlinux_kernel2.4.19
linuxlinux_kernel2.4.20
microsoftwindows_2000all versions
microsoftwindows_2000all versions
microsoftwindows_2000all versions
microsoftwindows_2000_terminal_servicesall versions
microsoftwindows_2000_terminal_servicesall versions
microsoftwindows_2000_terminal_servicesall versions
netbsdnetbsd1.5
netbsdnetbsd1.5.1
netbsdnetbsd1.5.2
netbsdnetbsd1.5.3
netbsdnetbsd1.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2003-0001