6.5

CVE-2010-0625

Stack-based buffer overflow in NWFTPD.nlm before 5.10.01 in the FTP server in Novell NetWare 5.1 through 6.5 SP8 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long (1) MKD, (2) RMD, (3) RNFR, or (4) DELE command.

Data is provided by the National Vulnerability Database (NVD)
NovellNetware Ftp Server Version5.01i
NovellNetware Ftp Server Version5.01o
NovellNetware Ftp Server Version5.01w
NovellNetware Ftp Server Version5.01y
NovellNetware Ftp Server Version5.02b
NovellNetware Ftp Server Version5.02i
NovellNetware Ftp Server Version5.02r
NovellNetware Ftp Server Version5.02y
NovellNetware Ftp Server Version5.03b
NovellNetware Ftp Server Version5.03l
NovellNetware Ftp Server Version5.04.5
NovellNetware Ftp Server Version5.04.8
NovellNetware Ftp Server Version5.04.20
NovellNetware Ftp Server Version5.04.25
NovellNetware Ftp Server Version5.05
NovellNetware Ftp Server Version5.05.04
NovellNetware Ftp Server Version5.06.04
NovellNetware Ftp Server Version5.06.05
NovellNetware Ftp Server Version5.07
NovellNetware Ftp Server Version5.07.02
NovellNetware Version5.1
NovellNetware Version5.1 Updatesp2a
NovellNetware Version5.1 Updatesp3
NovellNetware Version5.1 Updatesp4
NovellNetware Version5.1 Updatesp6
NovellNetware Version6.0
NovellNetware Version6.0 Updatesp1
NovellNetware Version6.0 Updatesp2
NovellNetware Version6.0 Updatesp3
NovellNetware Version6.5
NovellNetware Version6.5 Updatesp1
NovellNetware Version6.5 Updatesp1.1a
NovellNetware Version6.5 Updatesp1.1b
NovellNetware Version6.5 Updatesp2
NovellNetware Version6.5 Updatesp3
NovellNetware Version6.5 Updatesp4
NovellNetware Version6.5 Updatesp5
NovellNetware Version6.5 Updatesp6
NovellNetware Version6.5 Updatesp7
NovellNetware Version6.5 Updatesp8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 27.64% 0.963
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.