peter bassill · operator
$ cve CVE-2004-0375 JSON

CVE-2004-0375 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 8.8% (pctl 95)

Patch early

A public exploit exists.

Description

SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate Checksum Data option followed by a length of zero.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS8.83% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2004-08-18
Last modified2026-06-16

Affected (4)

VendorProduct
symantecclient firewall
symantecclient security
symantecnorton internet security
symantecnorton personal firewall

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD