CVE-2010-0317
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 10%
from disclosure to weapon0 days
Published on NVDJan 15
1st PoCJan 5
exploitation probability
10%top 5% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a large number of malformed or AFP requests that are not properly handled by (1) the CIFS functionality in CIFS.nlm Semantic Agent (Build 163 MP) 3.27 or (2) the AFP functionality in AFPTCP.nlm Build 163 SP 3.27. NOTE: some of these details are obtained from third party information.
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/11009cve_referencewww.exploit-db.com/exploits/11009unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://protekresearch.blogspot.com/2010/01/prl-cifsnlm-memory-consumption-denial.htmlhttp://secunia.com/advisories/38114https://exchange.xforce.ibmcloud.com/vulnerabilities/55389http://www.exploit-db.com/exploits/11009http://www.securityfocus.com/archive/1/508731/100/0/threadedhttp://www.securityfocus.com/bid/37616http://www.securitytracker.com/id?1023400http://www.vupen.com/english/advisories/2010/0041