CVE-2004-2767

Novell NetWare FTP Server - Denial of Service via DS Session Exhaustion

Title source: llm
STIX 2.1

Description

NWFTPD.nlm before 5.04.25 in the FTP server in Novell NetWare does not promptly close DS sessions, which allows remote attackers to cause a denial of service (connection slot exhaustion) by establishing many FTP sessions that persist for the lifetime of a DS session.

References (1)

Core 1
Core References

Scores

EPSS 0.0030
EPSS Percentile 53.3%

Details

CWE
CWE-264
Status published
Products (2)
novell/netware
novell/netware_ftp_server
Published Apr 05, 2010
Tracked Since Feb 18, 2026