5

CVE-2001-1244

Exploit

Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.

Data is provided by the National Vulnerability Database (NVD)
FreebsdFreebsd Version4.3
HpHp-ux Version11.00
HpHp-ux Version11.0.4
HpHp-ux Version11.11
HpVvos Version11.04
LinuxLinux Kernel Version2.4.0
LinuxLinux Kernel Version2.4.1
LinuxLinux Kernel Version2.4.2
LinuxLinux Kernel Version2.4.3
LinuxLinux Kernel Version2.4.4
LinuxLinux Kernel Version2.4.5
MicrosoftWindows 2000 Editionworkstation
MicrosoftWindows 2000 Updatesp1
MicrosoftWindows 2000 Updatesp2
MicrosoftWindows Nt Version4.0
MicrosoftWindows Nt Version4.0 Updatesp1
MicrosoftWindows Nt Version4.0 Updatesp2
MicrosoftWindows Nt Version4.0 Updatesp3
MicrosoftWindows Nt Version4.0 Updatesp4
MicrosoftWindows Nt Version4.0 Updatesp5
MicrosoftWindows Nt Version4.0 Updatesp6
MicrosoftWindows Nt Version4.0 Updatesp6a
NetbsdNetbsd Version1.5
NetbsdNetbsd Version1.5.1
OpenbsdOpenbsd Version2.8
OpenbsdOpenbsd Version2.9
SunSunos Version5.5.1
SunSunos Version5.7
SunSunos Version5.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 20.36% 0.954
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P