9.3
CVE-2003-0825
- EPSS 12.16%
- Veröffentlicht 03.03.2004 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:03:01
- Erkennungen
The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp1
Microsoft ≫ Windows 2000 Update sp2
Microsoft ≫ Windows 2000 Update sp3
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows 2003 Server Update r2 Edition x64
Microsoft ≫ Windows 2003 Server Version enterprise Edition 64-bit
Microsoft ≫ Windows 2003 Server Version enterprise_64-bit
Microsoft ≫ Windows 2003 Server Version r2 Edition datacenter_64-bit
Microsoft ≫ Windows 2003 Server Version standard Edition 64-bit
Microsoft ≫ Windows 2003 Server Version web
Microsoft ≫ Windows Nt Version 4.0 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Edition server
Microsoft ≫ Windows Nt Version 4.0 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp1 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp1 Edition server
Microsoft ≫ Windows Nt Version 4.0 Update sp1 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp2 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp2 Edition server
Microsoft ≫ Windows Nt Version 4.0 Update sp2 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp3 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp3 Edition server
Microsoft ≫ Windows Nt Version 4.0 Update sp3 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp4 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp4 Edition server
Microsoft ≫ Windows Nt Version 4.0 Update sp4 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp5 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp5 Edition server
Microsoft ≫ Windows Nt Version 4.0 Update sp5 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp6 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp6 Edition server
Microsoft ≫ Windows Nt Version 4.0 Update sp6 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp6a Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp6a Edition server
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 12.16% | 0.957 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.ciac.org/ciac/bulletins/o-077.shtml
http://www.kb.cert.org/vuls/id/445214
http://www.osvdb.org/3903
http://www.securityfocus.com/bid/9624
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-006
https://exchange.xforce.ibmcloud.com/vulnerabilities/15037
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A704
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A800
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A801
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A802