Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
Conclusion & alert: CVE-2004-0790 is rated High Exploit Risk (67.9/100): CVSS Medium severity, with high exploitation likelihood (EPSS 85.13%, 99th percentile). Core evidence: 3 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 948 | exploit_db | edb | 2005-04-20 | Exploit-DB ↗ |
| 942 | exploit_db | edb | 2005-04-17 | Exploit-DB ↗ |
| 25389 | exploit_db | edb | 2005-04-12 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-10-23 | 86.96% | 85.13% | -1.83% |
| 2 | 2025-10-01 | 85.13% | 86.96% | +1.83% |
| 3 | 2025-07-28 | — | 85.13% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2004-0790 medium priority: Ubuntu including 1 source packages (kernel-source-2.4.27), 4 status rows across 4 suites (dapper, edgy, feisty, upstream): released 2, DNE 1, needs-triage 1. | https://ubuntu.com/security/CVE-2004-0790 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| microsoft | windows_2000 | — | cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:* |
| microsoft | windows_2000 | — | cpe:2.3:o:microsoft:windows_2000:*:sp4:*:fr:*:*:*:* |
| microsoft | windows_2003_server | r2 | cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:* |
| microsoft | windows_98 | — | cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:* |
| microsoft | windows_98se | — | cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:* |
| microsoft | windows_me | — | cpe:2.3:o:microsoft:windows_me:*:*:*:*:*:*:*:* |
| microsoft | windows_xp | — | cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:* |
| microsoft | windows_xp | — | cpe:2.3:o:microsoft:windows_xp:*:sp1:64-bit:*:*:*:*:* |
| microsoft | windows_xp | — | cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:* |
| microsoft | windows_xp | — | cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:* |
| sun | solaris | 9.0 | cpe:2.3:o:sun:solaris:9.0:*:sparc:*:*:*:*:* |
| sun | solaris | 10.0 | cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:* |
| sun | sunos | 5.7 | cpe:2.3:o:sun:sunos:5.7:*:*:*:*:*:*:* |
| sun | sunos | 5.8 | cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:* |