Lucene search

K
cve[email protected]CVE-2010-4227
HistoryFeb 25, 2011 - 7:00 p.m.

CVE-2010-4227

2011-02-2519:00:00
CWE-119
web.nvd.nist.gov
18
cve-2010-4227
xnfs.nlm
novell netware 6.5
sp8
remote attackers
denial of service
execute arbitrary code
nfs
rpc
udp 1234
buffer overflow

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

High

0.94 High

EPSS

Percentile

99.2%

The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbitrary code via a crafted, signed value in a NFS RPC request to port UDP 1234, leading to a stack-based buffer overflow.

Affected configurations

NVD
Node
novellnetwareRange6.5sp7
OR
novellnetwareMatch6.5
OR
novellnetwareMatch6.5sp1
OR
novellnetwareMatch6.5sp2
OR
novellnetwareMatch6.5sp3
OR
novellnetwareMatch6.5sp4
OR
novellnetwareMatch6.5sp5
OR
novellnetwareMatch6.5sp6
CPENameOperatorVersion
novell:netwarenovell netwarele6.5

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

High

0.94 High

EPSS

Percentile

99.2%