peter bassill · operator
$ cve CVE-2003-0001 JSON

CVE-2003-0001 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 70.2% (pctl 99)

Patch early

A public exploit exists.

Description

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS70.24% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2003-01-17
Last modified2026-06-16

Affected (5)

VendorProduct
freebsdfreebsd
linuxlinux kernel
microsoftwindows 2000
microsoftwindows 2000 terminal services
netbsdnetbsd

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD