CVE-2004-0445

high

Description

The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name pointer that points to itself.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/16132

http://www.securityfocus.com/bid/10336

http://www.osvdb.org/6100

http://www.kb.cert.org/vuls/id/682110

http://www.ciac.org/ciac/bulletins/o-141.shtml

http://securitytracker.com/id?1010146

http://securitytracker.com/id?1010145

http://securitytracker.com/id?1010144

http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html

http://secunia.com/advisories/11066

http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021359.html

Details

Source: Mitre, NVD

Published: 2004-07-07

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 2.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High

EPSS

EPSS: 0.11048