CVE-1999-0414 describes a blind TCP spoofing vulnerability in Linux kernels prior to version 2.0.36, allowing remote attackers to inject data into the application layer before a TCP connection is fully established. This medium-severity vulnerability (CVSS 5.0) is network-exploitable with low complexity, potentially leading to information disclosure. While not actively exploited or on the KEV catalog, a public exploit (EDB-19458) exists, though there is no recorded community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.30CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.0.30:*:*:*:*:*:*:* | ||
2.0.35CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.0.35:*:*:*:*:*:*:* | ||
2.0.36CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.0.36:*:*:*:*:*:*:* | ||
2.0.37CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.0.37:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.