Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ncpfs

First CVE: Jan 10, 2005Active for: 22 yearsTotal CVEs: 8

Ncpfs is a network filesystem implementation for accessing Novell NetWare resources, deployed primarily on Linux and Unix systems where legacy network storage integration remains necessary. The vulnerability surface concentrates in the single ncpfs product and recurs through weakness classes including sensitive information disclosure, improper input validation, and symlink-following conditions that are endemic to filesystem-level code interfacing with untrusted network protocols. Public exploit code has an elevated tendency to be available for vulnerabilities in this product, reflecting both the accessibility of the attack surface and the historical interest in filesystem and protocol vulnerabilities. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
4.8
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ncpfs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2005
21 years ago
Most Recent CVE
Apr 10, 2011
5,584 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-0788MEDIUM
ncpfs 2.2.6 allows local users to cause a denial of service, obtain sensitive information, or possibly gain privileges via symlink attacks involving the (1) ncpmount and (2) ncpumo
Mar 2, 20104.425NOYES
CVE-2005-0014HIGH
Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.
May 2, 20057.520NONO
CVE-2005-0013HIGH
nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.
May 2, 20057.218NONO
CVE-2004-1079HIGH
Buffer overflow in (1) ncplogin and (2) ncpmap in nwclient.c for ncpfs 2.2.4, and possibly other versions, may allow local users to gain privileges via a long -T option.
Jan 10, 20057.218NONO
CVE-2011-1680MEDIUM
ncpmount in ncpfs 2.2.6 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.
Apr 10, 20114.417NONO
CVE-2011-1679LOW
ncpfs 2.2.6 and earlier attempts to use (1) ncpmount to append to the /etc/mtab file and (2) ncpumount to append to the /etc/mtab.tmp file without first checking whether resource l
Apr 10, 20113.315NONO
CVE-2010-0791LOW
The (1) ncpmount, (2) ncpumount, and (3) ncplogin programs in ncpfs 2.2.6 do not properly create lock files, which allows local users to cause a denial of service (application fail
Mar 10, 20102.112NONO
CVE-2010-0790LOW
sutil/ncpumount.c in ncpumount in ncpfs 2.2.6 produces certain detailed error messages about the results of privileged file-access attempts, which allows local users to determine t
Mar 10, 20102.112NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
38%
25%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ncpfs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ncpfs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ncpfs's Products

View all 1 CNAs →

Top CWEs