CVE-2010-4227

The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbitrary code via a crafted, signed value in a NFS RPC request to port UDP 1234, leading to a stack-based buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
novellnetware
𝑥
≤ 6.5
novellnetware
6.5
novellnetware
6.5:sp1
novellnetware
6.5:sp2
novellnetware
6.5:sp3
novellnetware
6.5:sp4
novellnetware
6.5:sp5
novellnetware
6.5:sp6
𝑥
= Vulnerable software versions