5
CVE-2003-0001
- EPSS 72.51%
- Veröffentlicht 17.01.2003 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:01:19
- Erkennungen
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version 2.4.1
Linux ≫ Linux Kernel Version 2.4.2
Linux ≫ Linux Kernel Version 2.4.3
Linux ≫ Linux Kernel Version 2.4.4
Linux ≫ Linux Kernel Version 2.4.5
Linux ≫ Linux Kernel Version 2.4.6
Linux ≫ Linux Kernel Version 2.4.7
Linux ≫ Linux Kernel Version 2.4.8
Linux ≫ Linux Kernel Version 2.4.9
Linux ≫ Linux Kernel Version 2.4.10
Linux ≫ Linux Kernel Version 2.4.11
Linux ≫ Linux Kernel Version 2.4.12
Linux ≫ Linux Kernel Version 2.4.13
Linux ≫ Linux Kernel Version 2.4.14
Linux ≫ Linux Kernel Version 2.4.15
Linux ≫ Linux Kernel Version 2.4.16
Linux ≫ Linux Kernel Version 2.4.17
Linux ≫ Linux Kernel Version 2.4.18
Linux ≫ Linux Kernel Version 2.4.19
Linux ≫ Linux Kernel Version 2.4.20
Microsoft ≫ Windows 2000 Update sp1
Microsoft ≫ Windows 2000 Update sp2
Microsoft ≫ Windows 2000 Terminal Services Update sp1
Microsoft ≫ Windows 2000 Terminal Services Update sp2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 72.51% | 0.994 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.redhat.com/support/errata/RHSA-2003-088.html
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html
http://marc.info/?l=bugtraq&m=104222046632243&w=2
http://secunia.com/advisories/7996
http://www.atstake.com/research/advisories/2003/a010603-1.txt
http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf
http://www.kb.cert.org/vuls/id/412115
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
http://www.osvdb.org/9962
http://www.redhat.com/support/errata/RHSA-2003-025.html
http://www.securityfocus.com/archive/1/305335/30/26420/threaded
http://www.securityfocus.com/archive/1/307564/30/26270/threaded
http://www.securitytracker.com/id/1031583
http://www.securitytracker.com/id/1040185
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2665