CVE-2010-4227

Novell Netware < 6.5 - Memory Corruption

Title source: rule

Description

The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbitrary code via a crafted, signed value in a NFS RPC request to port UDP 1234, leading to a stack-based buffer overflow.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Francis Provencher · rubydosnetware
https://www.exploit-db.com/exploits/16234

Scores

EPSS 0.3845
EPSS Percentile 97.3%

Details

CWE
CWE-119
Status published
Products (2)
novell/netware 6.5 (7 CPE variants)
novell/netware < 6.5
Published Feb 25, 2011
Tracked Since Feb 18, 2026