cbcvebase.
CVE-2003-0850
published 2003-11-17

CVE-2003-0850: The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge…

PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.68%
88.4th percentile
The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets."

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlibnids< libnids 1.18-1 (bookworm)libnids 1.18-1 (bookworm)
dug_songdsniff
libnids_projectlibnids>= 0 < 1.18-11.18-1
libnids_projectlibnids>= 0 < 1.18-11.18-1
libnids_projectlibnids>= 0 < 1.18-11.18-1
libnids_projectlibnids>= 0 < 1.18-11.18-1
rafal_wojtczuklibnids
rafal_wojtczuklibnids
rafal_wojtczuklibnids
rafal_wojtczuklibnids
rafal_wojtczuklibnids
rafal_wojtczuklibnids

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.