5
CVE-2003-0001
- EPSS 3.45%
- Veröffentlicht 17.01.2003 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version2.4.1
Linux ≫ Linux Kernel Version2.4.2
Linux ≫ Linux Kernel Version2.4.3
Linux ≫ Linux Kernel Version2.4.4
Linux ≫ Linux Kernel Version2.4.5
Linux ≫ Linux Kernel Version2.4.6
Linux ≫ Linux Kernel Version2.4.7
Linux ≫ Linux Kernel Version2.4.8
Linux ≫ Linux Kernel Version2.4.9
Linux ≫ Linux Kernel Version2.4.10
Linux ≫ Linux Kernel Version2.4.11
Linux ≫ Linux Kernel Version2.4.12
Linux ≫ Linux Kernel Version2.4.13
Linux ≫ Linux Kernel Version2.4.14
Linux ≫ Linux Kernel Version2.4.15
Linux ≫ Linux Kernel Version2.4.16
Linux ≫ Linux Kernel Version2.4.17
Linux ≫ Linux Kernel Version2.4.18
Linux ≫ Linux Kernel Version2.4.19
Linux ≫ Linux Kernel Version2.4.20
Microsoft ≫ Windows 2000 Updatesp1
Microsoft ≫ Windows 2000 Updatesp2
Microsoft ≫ Windows 2000 Terminal Services Updatesp1
Microsoft ≫ Windows 2000 Terminal Services Updatesp2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 3.45% | 0.871 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.