{"api_version":"1","generated_at":"2026-07-23T06:14:45+00:00","cve":"CVE-2003-0291","urls":{"html":"https://cve.report/CVE-2003-0291","api":"https://cve.report/api/cve/CVE-2003-0291.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-0291","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-0291"},"summary":{"title":"CVE-2003-0291","description":"3com OfficeConnect Remote 812 ADSL Router 1.1.7 does not properly clear memory from DHCP responses, which allows remote attackers to identify the contents of previous HTTP requests by sniffing DHCP packets.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-06-16 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/7592","name":"http://www.securityfocus.com/bid/7592","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"3Com OfficeConnect ADSL Router DHCP Response Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11999","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11999","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=105292451702516&w=2","name":"http://marc.info/?l=bugtraq&m=105292451702516&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=105301488426951&w=2","name":"http://marc.info/?l=bugtraq&m=105301488426951&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm","name":"http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"コエンザイムQ10（粉末・顆粒）の特徴｜コエンザイムQ10飲み比べ！-CoQ10Web-","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-0291","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0291","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"291","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"3com","cpe5":"3cp4144","cpe6":"1.1.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:50:47.333Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm"},{"name":"20030515 RE : Memory leak in 3COM DSL routers","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=105301488426951&w=2"},{"name":"7592","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/7592"},{"name":"3com-officeconnect-memory-leak(11999)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11999"},{"name":"20030514 Memory leak in 3COM 812 DSL routers","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=105292451702516&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-05-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"3com OfficeConnect Remote 812 ADSL Router 1.1.7 does not properly clear memory from DHCP responses, which allows remote attackers to identify the contents of previous HTTP requests by sniffing DHCP packets."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm"},{"name":"20030515 RE : Memory leak in 3COM DSL routers","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=105301488426951&w=2"},{"name":"7592","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/7592"},{"name":"3com-officeconnect-memory-leak(11999)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11999"},{"name":"20030514 Memory leak in 3COM 812 DSL routers","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=105292451702516&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-0291","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"3com OfficeConnect Remote 812 ADSL Router 1.1.7 does not properly clear memory from DHCP responses, which allows remote attackers to identify the contents of previous HTTP requests by sniffing DHCP packets."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm","refsource":"MISC","url":"http://nautopia.coolfreepages.com/vulnerabilidades/3com812_dhcp_leak.htm"},{"name":"20030515 RE : Memory leak in 3COM DSL routers","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=105301488426951&w=2"},{"name":"7592","refsource":"BID","url":"http://www.securityfocus.com/bid/7592"},{"name":"3com-officeconnect-memory-leak(11999)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11999"},{"name":"20030514 Memory leak in 3COM 812 DSL routers","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=105292451702516&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-0291","datePublished":"2003-05-15T04:00:00.000Z","dateReserved":"2003-05-14T00:00:00.000Z","dateUpdated":"2024-08-08T01:50:47.333Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-06-16 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:3com:3cp4144:1.1.7:*:*:*:*:*:*:*","matchCriteriaId":"3BA4FE31-7801-42E2-8E27-BCC6085D37A1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"291","Ordinal":"1","Title":"CVE-2003-0291","CVE":"CVE-2003-0291","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"291","Ordinal":"1","NoteData":"3com OfficeConnect Remote 812 ADSL Router 1.1.7 does not properly clear memory from DHCP responses, which allows remote attackers to identify the contents of previous HTTP requests by sniffing DHCP packets.","Type":"Description","Title":"CVE-2003-0291"},{"CveYear":"2003","CveId":"291","Ordinal":"2","NoteData":"2003-05-15","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"291","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}