Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2003-0356

Опубликовано: 09 июн. 2003
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ethereal:ethereal:*:*:*:*:*:*:*:*
Версия до 0.9.12 (исключая)

EPSS

Процентиль: 95%
0.09574
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-193

Связанные уязвимости

redhat
около 23 лет назад

Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.

CVSS3: 9.8
debian
около 23 лет назад

Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier all ...

CVSS3: 9.8
github
больше 4 лет назад

Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.

EPSS

Процентиль: 95%
0.09574
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-193