Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.
Conclusion & alert: CVE-2001-1244 is rated High Exploit Risk (72.9/100): CVSS Medium severity, with high exploitation likelihood (EPSS 20.73%, 97th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +3.93% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 20997 | exploit_db | edb | 2001-07-07 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 16.80% | 20.73% | +3.93% |
| 2 | 2026-01-10 | 19.59% | 16.80% | -2.79% |
| 3 | 2025-12-28 | — | 19.59% | — |
Full EPSS history (17 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| freebsd | freebsd | 4.3 | cpe:2.3:o:freebsd:freebsd:4.3:*:*:*:*:*:*:* |
| hp | hp-ux | 11.00 | cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:* |
| hp | hp-ux | 11.0.4 | cpe:2.3:o:hp:hp-ux:11.0.4:*:*:*:*:*:*:* |
| hp | hp-ux | 11.11 | cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:* |
| hp | vvos | 11.04 | cpe:2.3:o:hp:vvos:11.04:*:*:*:*:*:*:* |
| linux | linux_kernel | 2.4.0 | cpe:2.3:o:linux:linux_kernel:2.4.0:*:*:*:*:*:*:* |
| linux | linux_kernel | 2.4.1 | cpe:2.3:o:linux:linux_kernel:2.4.1:*:*:*:*:*:*:* |
| linux | linux_kernel | 2.4.2 | cpe:2.3:o:linux:linux_kernel:2.4.2:*:*:*:*:*:*:* |
| linux | linux_kernel | 2.4.3 | cpe:2.3:o:linux:linux_kernel:2.4.3:*:*:*:*:*:*:* |
| linux | linux_kernel | 2.4.4 | cpe:2.3:o:linux:linux_kernel:2.4.4:*:*:*:*:*:*:* |
| linux | linux_kernel | 2.4.5 | cpe:2.3:o:linux:linux_kernel:2.4.5:*:*:*:*:*:*:* |
| microsoft | windows_2000 | — | cpe:2.3:o:microsoft:windows_2000:*:*:workstation:*:*:*:*:* |
| microsoft | windows_2000 | — | cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:* |
| microsoft | windows_2000 | — | cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:* |
| microsoft | windows_nt | 4.0 | cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:* |
| microsoft | windows_nt | 4.0 | cpe:2.3:o:microsoft:windows_nt:4.0:sp1:*:*:*:*:*:* |
| microsoft | windows_nt | 4.0 | cpe:2.3:o:microsoft:windows_nt:4.0:sp2:*:*:*:*:*:* |
| microsoft | windows_nt | 4.0 | cpe:2.3:o:microsoft:windows_nt:4.0:sp3:*:*:*:*:*:* |
| microsoft | windows_nt | 4.0 | cpe:2.3:o:microsoft:windows_nt:4.0:sp4:*:*:*:*:*:* |
| microsoft | windows_nt | 4.0 | cpe:2.3:o:microsoft:windows_nt:4.0:sp5:*:*:*:*:*:* |
| microsoft | windows_nt | 4.0 | cpe:2.3:o:microsoft:windows_nt:4.0:sp6:*:*:*:*:*:* |
| microsoft | windows_nt | 4.0 | cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:*:*:*:*:*:* |
| netbsd | netbsd | 1.5 | cpe:2.3:o:netbsd:netbsd:1.5:*:*:*:*:*:*:* |
| netbsd | netbsd | 1.5.1 | cpe:2.3:o:netbsd:netbsd:1.5.1:*:*:*:*:*:*:* |
| openbsd | openbsd | 2.8 | cpe:2.3:o:openbsd:openbsd:2.8:*:*:*:*:*:*:* |
| openbsd | openbsd | 2.9 | cpe:2.3:o:openbsd:openbsd:2.9:*:*:*:*:*:*:* |
| sun | sunos | 5.5.1 | cpe:2.3:o:sun:sunos:5.5.1:*:*:*:*:*:*:* |
| sun | sunos | 5.7 | cpe:2.3:o:sun:sunos:5.7:*:*:*:*:*:*:* |
| sun | sunos | 5.8 | cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.securityfocus.com/archive/1/195457 | |
| http://www.securityfocus.com/bid/2997 | Exploit Vendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/6824 |