CVE-2004-0375 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 8.8% (pctl 95)
Patch early
A public exploit exists.
Description
SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate Checksum Data option followed by a length of zero.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| EPSS | 8.83% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-08-18 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| symantec | client firewall |
| symantec | client security |
| symantec | norton internet security |
| symantec | norton personal firewall |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Symantec Client Firewall Products 5 - 'SYMNDIS.SYS' Driver Remote Denial of Service | 2004-03-18 |
References
- http://marc.info/?l=bugtraq&m=108275582432246&w=2
- http://securitytracker.com/id?1009379
- http://securitytracker.com/id?1009380
- http://www.eeye.com/html/Research/Upcoming/20040309.html
- http://www.securityfocus.com/bid/9912
- http://www.symantec.com/avcenter/security/Content/2004.04.20.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15433
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15936
- http://marc.info/?l=bugtraq&m=108275582432246&w=2
- http://securitytracker.com/id?1009379
- http://securitytracker.com/id?1009380
- http://www.eeye.com/html/Research/Upcoming/20040309.html
- http://www.securityfocus.com/bid/9912
- http://www.symantec.com/avcenter/security/Content/2004.04.20.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15433
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15936
→ the Explorer · watch your stack · NVD