CVE-2006-2304 describes multiple integer overflows within the DPRPC library (DPRPCW32.DLL) in specific versions of Novell Client (4.83 SP3, 4.90 SP2, and 4.91 SP2). This critical vulnerability, with a CVSS score of 10.0, allows unauthenticated remote attackers to execute arbitrary code by sending specially crafted XDR encoded arrays. While no active exploitation or public exploit code is noted, and community discussion is minimal, its high severity and remote attack vector warrant attention for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.83CPE matchmatch criteria | cpe:2.3:a:novell:client:4.83:sp3:*:*:*:*:*:* | ||
4.90CPE matchmatch criteria | cpe:2.3:a:novell:client:4.90:sp2:*:*:*:*:*:* | ||
4.91CPE matchmatch criteria | cpe:2.3:a:novell:client:4.91:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.