Unrated severityNVD Advisory· Published Dec 19, 2000· Updated Sep 23, 2026
CVE-2000-0916
CVE-2000-0916
Description
FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:o:freebsd:freebsd:2.0:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:o:freebsd:freebsd:2.0:*:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:3.0:*:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:4.0:*:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:4.1.1:*:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:4.1:*:*:*:*:*:*:*
- (no CPE)range: <=4.1.1
Patches
Vulnerability mechanics
References
2- ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:52.tcp-iss.ascnvdPatchVendor Advisory
- www.securityfocus.com/bid/1766nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.