5.4

CVE-2008-1441

Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "PGM Malformed Fragment Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows Server 2003 Version- HwPlatformx64
MicrosoftWindows Server 2003 Version- Updatesp1
MicrosoftWindows Server 2003 Version- Updatesp1 HwPlatformitanium
MicrosoftWindows Server 2003 Version- Updatesp2
MicrosoftWindows Server 2003 Version- Updatesp2 HwPlatformitanium
MicrosoftWindows Server 2003 Version- Updatesp2 HwPlatformx64
MicrosoftWindows Server 2008 Version- HwPlatformitanium
MicrosoftWindows Server 2008 Version- HwPlatformx64
MicrosoftWindows Vista Version-
MicrosoftWindows Vista Version- HwPlatformx64
MicrosoftWindows Vista Version- Updatesp1
MicrosoftWindows Vista Version- Updatesp1 HwPlatformx64
MicrosoftWindows Xp Version- SwEditionprofessional HwPlatformx64
MicrosoftWindows Xp Version- Updatesp2
MicrosoftWindows Xp Version- Updatesp2 SwEditionprofessional HwPlatformx64
MicrosoftWindows Xp Version- Updatesp3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 59.91% 0.982
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 4.9 6.9
AV:N/AC:H/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.