VulnerabilityModified
CVE-2006-6306
Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.
LOW 1.2EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.
- CVSS 2.0
- 1.2 LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Affected
- novell/client
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051038.htmlVendor Advisory
- http://secunia.com/advisories/23363
- http://securityreason.com/securityalert/1970
- http://securitytracker.com/id?1017377
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974872.htm
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974876.htm
- http://www.layereddefense.com/Novell01DEC.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/453176/100/0/threaded
- http://www.vupen.com/english/advisories/2006/4987
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30644
- https://secure-support.novell.com/KanisaPlatform/Publishing/372/3546910_f.SAL_Public.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051038.htmlVendor Advisory
- http://secunia.com/advisories/23363
- http://securityreason.com/securityalert/1970
- http://securitytracker.com/id?1017377
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974872.htm
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974876.htm
- http://www.layereddefense.com/Novell01DEC.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/453176/100/0/threaded
- http://www.vupen.com/english/advisories/2006/4987
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30644
- https://secure-support.novell.com/KanisaPlatform/Publishing/372/3546910_f.SAL_Public.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.