← All CVEs

CVE-2010-4227

high · 10

The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbitrary code via a crafted, signed value in a NFS RPC request to port UDP 1234, leading to a stack-based buffer overflow.

10
CVSS
16.8%
EPSS (exploit prob.)
97th
EPSS percentile
2011-02-25
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
novellnetware<= 6.5
novellnetware6.5
novellnetware6.5
novellnetware6.5
novellnetware6.5
novellnetware6.5
novellnetware6.5
novellnetware6.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-4227