CVE-2005-3659
Last modified
CVE-2005-3659 is a vulnerability of currently unknown severity. nsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allows remote attackers to cause a denial of service (nsrd service crash) via a malformed RPC request to RPC program number 390109, which triggers a null dereference.. EPSS estimates a 2.44% chance of exploitation in the next 30 days.
Description
nsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allows remote attackers to cause a denial of service (nsrd service crash) via a malformed RPC request to RPC program number 390109, which triggers a null dereference.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Emc | Legato Networker | 7.2 |
| Emc | Legato Networker | 7.2.1 |
| Emc | Legato Networker | 7.2_build172 |
References
- http://secunia.com/advisories/18495Exploit, Patch, Vendor Advisory
- http://secunia.com/advisories/18615Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0233Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0343Vendor Advisory
- http://secunia.com/advisories/18495Exploit, Patch, Vendor Advisory
- http://secunia.com/advisories/18615Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0233Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0343Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3659?
How severe is CVE-2005-3659?
How do I fix CVE-2005-3659?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-3653Heap-based buffer overflow in the iGateway service for vario…
- CVE-2005-3654Blue Coat Systems Inc. WinProxy before 6.1a allows remote at…
- CVE-2005-3655Heap-based buffer overflow in Novell Open Enterprise Server …
- CVE-2005-3656Multiple format string vulnerabilities in logging functions …
- CVE-2005-3657The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Sec…
- CVE-2005-3658Multiple heap-based buffer overflows in EMC Legato NetWorker…
- CVE-2005-3660Linux kernel 2.4 and 2.6 allows attackers to cause a denial …
- CVE-2005-3661Dell TrueMobile 2300 Wireless Broadband Router running firmw…
- CVE-2005-3662Off-by-one buffer overflow in pnmtopng before 2.39, when usi…
- CVE-2005-3663Unquoted Windows search path vulnerability in Kaspersky Anti…
- CVE-2005-3664Heap-based buffer overflow in Kaspersky Anti-Virus Engine, a…
- CVE-2005-3665Multiple cross-site scripting (XSS) vulnerabilities in phpMy…
Are you affected by CVE-2005-3659?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
