SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-6306

Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.

LOW 1.2EPSS 0.36%

Does this matter?

Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.

Description

Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.

CVSS 2.0
1.2 LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
EPSS
0.36% probability · 30th percentile
CISA KEV
Not listed
Affected
novell/client
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.