{
    "id": "CVE-2003-0001",
    "published": "2003-01-17 05:00:00",
    "last_modified": "2026-06-16 22:01:19",
    "cvss_score": "5.0",
    "cvss_severity": "MEDIUM",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
    "cwe": "CWE-200",
    "description": "Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.",
    "epss_score": "0.70235",
    "epss_percentile": "0.99364",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:14:13",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "freebsd",
            "product": "freebsd"
        },
        {
            "vendor": "linux",
            "product": "linux_kernel"
        },
        {
            "vendor": "microsoft",
            "product": "windows_2000"
        },
        {
            "vendor": "microsoft",
            "product": "windows_2000_terminal_services"
        },
        {
            "vendor": "netbsd",
            "product": "netbsd"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "26076",
            "title": "Cisco ASA < 8.4.4.6 < 8.2.5.32 - Ethernet Information Leak",
            "date": "2013-06-10",
            "url": "https://www.exploit-db.com/exploits/26076"
        },
        {
            "source": "exploit-db",
            "ref_id": "22131",
            "title": "Linux Kernel 2.0.x/2.2.x/2.4.x (FreeBSD 4.x) - Network Device Driver Frame Padding Information Disclosure",
            "date": "2007-03-23",
            "url": "https://www.exploit-db.com/exploits/22131"
        },
        {
            "source": "exploit-db",
            "ref_id": "3555",
            "title": "Ethernet Device Drivers Frame Padding - 'Etherleak' Infomation Leakage",
            "date": "2007-03-23",
            "url": "https://www.exploit-db.com/exploits/3555"
        }
    ],
    "refs_list": [
        "http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html",
        "http://marc.info/?l=bugtraq&m=104222046632243&w=2",
        "http://secunia.com/advisories/7996",
        "http://www.atstake.com/research/advisories/2003/a010603-1.txt",
        "http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf",
        "http://www.kb.cert.org/vuls/id/412115",
        "http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html",
        "http://www.osvdb.org/9962",
        "http://www.redhat.com/support/errata/RHSA-2003-025.html",
        "http://www.redhat.com/support/errata/RHSA-2003-088.html",
        "http://www.securityfocus.com/archive/1/305335/30/26420/threaded",
        "http://www.securityfocus.com/archive/1/307564/30/26270/threaded",
        "http://www.securitytracker.com/id/1031583",
        "http://www.securitytracker.com/id/1040185",
        "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2665",
        "http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html",
        "http://marc.info/?l=bugtraq&m=104222046632243&w=2",
        "http://secunia.com/advisories/7996",
        "http://www.atstake.com/research/advisories/2003/a010603-1.txt",
        "http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf",
        "http://www.kb.cert.org/vuls/id/412115",
        "http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html",
        "http://www.osvdb.org/9962",
        "http://www.redhat.com/support/errata/RHSA-2003-025.html",
        "http://www.redhat.com/support/errata/RHSA-2003-088.html"
    ]
}