cbcvebase.
CVE-2005-3534
published 2005-12-22

CVE-2005-3534: Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a…

PriorityP337high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.99%
92.5th percentile
Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiannbd< nbd 1:2.9.16-8 (bookworm)nbd 1:2.9.16-8 (bookworm)
debiannbd< nbd 1:2.8.3-1 (bookworm)nbd 1:2.8.3-1 (bookworm)
wouter_verhelstnbd<= 2.7.5
wouter_verhelstnbd<= 2.9.19
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd
wouter_verhelstnbd

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.