Netware

Vendor:

First CVE: Sep 16, 1993 · Active for 32 years

76
Total CVEs
More Total CVEs than 99% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Netware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 1993
32 years ago
Most Recent CVE
Mar 3, 2021
1,971 days ago

CVE Severity & Scoring

Netware76 CVEs
All CVEs352,719 CVEs
LowMediumHigh
Attack Vector
Local2 (2.6%)
Network0 (0.0%)
Unknown74 (97.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (2.6%)
High0 (0.0%)
Unknown74 (97.4%)
User Interaction
None2 (2.6%)
Unknown74 (97.4%)
Required0 (0.0%)
Privileges Required
Low1 (1.3%)
High0 (0.0%)
None1 (1.3%)
Unknown74 (97.4%)

Top CVEs

Signals from CVEs in this product scope (76 CVEs).

76 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Exp
May 14, 20097.256NOYES
The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbitrary code via a crafted, sign
Feb 25, 201110.051NOYES
Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a denial of service (ABEND) via an incorrect password length, as
Sep 8, 20055.051NOYES
Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated users to execute arbitrary code or cause a denial of servic
Mar 22, 20119.047NOYES
Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitrary code via a Sessions Setup
Jun 21, 201010.044NOYES
Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute arbitrary code or cause a denial of service (ab
Nov 30, 20117.536NOYES
Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string.
Aug 27, 20035.034NOYES
Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a large number of malformed or AFP
Jan 15, 20107.833NOYES
Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2) allfield.jse, (3) websinfo.bas, (4) ndslogin.pl,
Dec 31, 20025.032NOYES
The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request.
Apr 11, 20037.531NOYES

Exploit Exposure

Signals from CVEs in this product scope (76 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.3% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
15 CVEs
19.7% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (76 CVEs).

Media Mentions

Signals from CVEs in this product scope (76 CVEs).

Top CNAs Publishing CVEs For Netware

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.5306.96.1%06
6.0276.26.8%06
5.1276.07.8%08
5.056.77.7%03
4.1137.53.9%01
4.137.53.9%01
4.0114.60.4%00
4.024.81.9%01
3.1215.01.1%00