peter bassill · operator
$ cve CVE-2010-4228 JSON

CVE-2010-4228 EXPLOIT

9.0
HIGH · CVSS 2.0 · EPSS 14.7% (pctl 97)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated users to execute arbitrary code or cause a denial of service (abend) via a long DELE command, a different vulnerability than CVE-2010-0625.4.

Scoring

CVSS9.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS14.66% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2011-03-22
Last modified2026-06-16

Affected (1)

VendorProduct
novellnetware

Public exploits

SourceTitleDate
exploit-dbNovell Netware - NWFTPD.NLM DELE Remote Code Execution2011-03-21

References

→ the Explorer  ·  watch your stack  ·  NVD