5
CVSSv2

CVE-2004-1109

Published: 10/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and previous versions allows remote malicious users to cause a denial of service (CPU consumption and system freeze from infinite loop) via a (1) TCP, (2) UDP, or (3) ICMP packet with a zero length IP Option field.

Vulnerable Product Search on Vulmon Subscribe to Product

kerio personal firewall 4.0.6

kerio personal firewall 4.0.7

kerio personal firewall 4.0.8

kerio personal firewall 4.0.9

kerio personal firewall 4.0.10

kerio personal firewall 4.0.16

kerio personal firewall 4.1

kerio personal firewall 4.1.1

Exploits

/* HOD-kerio-firewall-DoS-explc: 2004-11-10 * * Copyright (c) 2004 houseofdabus * * Kerio Personal Firewall Multiple IP Options Denial of Service PoC * * Coded by * * * ::[ houseofdabus ]:: * * * * Bug discoveried by eEye: * wwweeyecom/html/research/advisories/AD20041109html * * ----------------------------------------- ...