Vulnerability Details CVE-2003-0356
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.096
EPSS Ranking 94.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2003-0356
-
cpe:2.3:a:ethereal:ethereal:-
-
cpe:2.3:a:ethereal:ethereal:0.8.13
-
cpe:2.3:a:ethereal:ethereal:0.9.11
-
cpe:2.3:a:ethereal:ethereal:0.9.3