CVE-2003-0001
medium · 5Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
5
CVSS
70.2%
EPSS (exploit prob.)
99th
EPSS percentile
2003-01-17
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| freebsd | freebsd | 4.2 |
| freebsd | freebsd | 4.3 |
| freebsd | freebsd | 4.4 |
| freebsd | freebsd | 4.5 |
| freebsd | freebsd | 4.6 |
| freebsd | freebsd | 4.7 |
| linux | linux_kernel | 2.4.1 |
| linux | linux_kernel | 2.4.2 |
| linux | linux_kernel | 2.4.3 |
| linux | linux_kernel | 2.4.4 |
| linux | linux_kernel | 2.4.5 |
| linux | linux_kernel | 2.4.6 |
| linux | linux_kernel | 2.4.7 |
| linux | linux_kernel | 2.4.8 |
| linux | linux_kernel | 2.4.9 |
| linux | linux_kernel | 2.4.10 |
| linux | linux_kernel | 2.4.11 |
| linux | linux_kernel | 2.4.12 |
| linux | linux_kernel | 2.4.13 |
| linux | linux_kernel | 2.4.14 |
| linux | linux_kernel | 2.4.15 |
| linux | linux_kernel | 2.4.16 |
| linux | linux_kernel | 2.4.17 |
| linux | linux_kernel | 2.4.18 |
| linux | linux_kernel | 2.4.19 |
| linux | linux_kernel | 2.4.20 |
| microsoft | windows_2000 | all versions |
| microsoft | windows_2000 | all versions |
| microsoft | windows_2000 | all versions |
| microsoft | windows_2000_terminal_services | all versions |
| microsoft | windows_2000_terminal_services | all versions |
| microsoft | windows_2000_terminal_services | all versions |
| netbsd | netbsd | 1.5 |
| netbsd | netbsd | 1.5.1 |
| netbsd | netbsd | 1.5.2 |
| netbsd | netbsd | 1.5.3 |
| netbsd | netbsd | 1.6 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html
- http://marc.info/?l=bugtraq&m=104222046632243&w=2
- http://secunia.com/advisories/7996
- http://www.atstake.com/research/advisories/2003/a010603-1.txt
- http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf
- http://www.kb.cert.org/vuls/id/412115
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.osvdb.org/9962
- http://www.redhat.com/support/errata/RHSA-2003-025.html
- http://www.redhat.com/support/errata/RHSA-2003-088.html
- http://www.securityfocus.com/archive/1/305335/30/26420/threaded
- http://www.securityfocus.com/archive/1/307564/30/26270/threaded
- http://www.securitytracker.com/id/1031583
- http://www.securitytracker.com/id/1040185
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2665
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html
- http://marc.info/?l=bugtraq&m=104222046632243&w=2
- http://secunia.com/advisories/7996
- http://www.atstake.com/research/advisories/2003/a010603-1.txt
- http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf
- http://www.kb.cert.org/vuls/id/412115
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.osvdb.org/9962
- http://www.redhat.com/support/errata/RHSA-2003-025.html
- http://www.redhat.com/support/errata/RHSA-2003-088.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2003-0001