Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2003-0807 | First vendor Publication | 2004-06-01 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0807 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:1030 | |||
Oval ID: | oval:org.mitre.oval:def:1030 | ||
Title: | Windows Server 2003 COM Internet Services/RPC over HTTP Proxy Component Buffer Overflow | ||
Description: | Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2003-0807 | Version: | 2 |
Platform(s): | Microsoft Windows Server 2003 | Product(s): | COM Internet Services |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:969 | |||
Oval ID: | oval:org.mitre.oval:def:969 | ||
Title: | Windows NT COM Internet Services/RPC over HTTP Proxy Component Buffer Overflow | ||
Description: | Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2003-0807 | Version: | 3 |
Platform(s): | Microsoft Windows NT | Product(s): | COM Internet Services |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:995 | |||
Oval ID: | oval:org.mitre.oval:def:995 | ||
Title: | Windows 2000 COM Internet Services/RPC over HTTP Proxy Component Buffer Overflow | ||
Description: | Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2003-0807 | Version: | 1 |
Platform(s): | Microsoft Windows 2000 | Product(s): | COM Internet Services |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 1 | |
Os | 1 | |
Os | 2 | |
Os | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2009-11-16 | Name : Microsoft RPC Interface Buffer Overrun (KB824146) File : nvt/msrpc_dcom2.nasl |
2005-11-03 | Name : Microsoft RPC Interface Buffer Overrun (823980) File : nvt/msrpc_dcom.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
5246 | Microsoft Windows CIS/RPC Over HTTP DoS Microsoft Windows contains a flaw that may allow a remote denial of service. The issue is triggered due to the COM Internet Service (CIS) and RPC over HTTP Proxy components, which do not properly validate message input. With a specially crafted message, a remote attacker could cause the components to stop responding resulting in loss of availability. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | SMB-DS DCEPRC ORPCThis request flood attempt RuleID : 2496 - Revision : 14 - Type : NETBIOS |
2014-01-10 | SMB DCEPRC ORPCThis request flood attempt RuleID : 2495 - Revision : 14 - Type : NETBIOS |
2014-01-10 | DCEPRC ORPCThis request flood attempt RuleID : 2494 - Revision : 14 - Type : NETBIOS |
2014-01-10 | DCERPC ISystemActivate flood attempt RuleID : 21262 - Revision : 6 - Type : OS-WINDOWS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-03-16 | Name : Arbitrary code can be executed on the remote host. File : smb_kb828741.nasl - Type : ACT_GATHER_INFO |
2004-04-13 | Name : Arbitrary code can be executed on the remote host. File : smb_nt_ms04-012.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:03 |
|
2024-11-28 12:05:43 |
|
2021-05-04 12:01:59 |
|
2021-04-22 01:02:15 |
|
2020-05-23 00:15:30 |
|
2018-10-13 00:22:27 |
|
2017-10-11 09:23:18 |
|
2017-07-11 12:01:18 |
|
2016-04-26 12:37:32 |
|
2014-02-17 10:26:36 |
|
2013-05-11 11:53:02 |
|