CVE-2003-0001
45Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 70%
from disclosure to weapon1535 days
Published on NVDJan 8
1st PoC+1535d
exploitation probability
70%top 1% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
Affected products
n/a · n/apublic PoCs found — 4✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/22131exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/3555exploitdbwww.exploit-db.com/exploits/26076unverifiedgithubgithub.com/marb08/etherleak-checker★ 5⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.htmlhttp://marc.info/?l=bugtraq&m=104222046632243&w=2http://secunia.com/advisories/7996https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2665http://www.atstake.com/research/advisories/2003/a010603-1.txthttp://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdfhttp://www.kb.cert.org/vuls/id/412115http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.osvdb.org/9962http://www.redhat.com/support/errata/RHSA-2003-025.htmlhttp://www.redhat.com/support/errata/RHSA-2003-088.htmlhttp://www.securityfocus.com/archive/1/305335/30/26420/threaded