{"api_version":"1","generated_at":"2026-07-23T09:58:23+00:00","cve":"CVE-2007-2954","urls":{"html":"https://cve.report/CVE-2007-2954","api":"https://cve.report/api/cve/CVE-2007-2954.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2954","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2954"},"summary":{"title":"CVE-2007-2954","description":"Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2 through SP4 for Windows allow remote attackers to execute arbitrary code via certain long arguments to the (1) RpcAddPrinterDriver, (2) RpcGetPrinterDriverDirectory, and other unspecified RPC requests, aka Novell bug 300870, a different vulnerability than CVE-2006-5854.","state":"PUBLISHED","assigner":"flexera","published_at":"2007-08-31 22:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.zerodayinitiative.com/advisories/ZDI-07-045/","name":"http://www.zerodayinitiative.com/advisories/ZDI-07-045/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/secunia_research/2007-57/advisory/","name":"http://secunia.com/secunia_research/2007-57/advisory/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Novell Client NWSPOOL.DLL Buffer Overflow Vulnerabilities - Secunia Research - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://download.novell.com/Download?buildid=VOXNZb-6t_g~","name":"http://download.novell.com/Download?buildid=VOXNZb-6t_g~","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Downloads - Novell Client 4.91 Post-SP2/3/4 NWSPOOL.DLL","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25474","name":"http://www.securityfocus.com/bid/25474","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Novell Client NWSPOOL.DLL RPC Request Multiple Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35824","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35824","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/3006","name":"http://www.vupen.com/english/advisories/2007/3006","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1018623","name":"http://securitytracker.com/id?1018623","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Novell Client NWSPOOL.DLL Stack Overflows Let Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26374","name":"http://secunia.com/advisories/26374","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Novell Client NWSPOOL.DLL Buffer Overflow Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/37321","name":"http://osvdb.org/37321","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2954","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2954","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2954","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"client","cpe6":"4.91","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2954","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"client","cpe6":"4.91","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2954","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"client","cpe6":"4.91","cpe7":"sp4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:57:54.748Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2007-3006","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3006"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://download.novell.com/Download?buildid=VOXNZb-6t_g~"},{"name":"novell-client-nwspool-bo(35824)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35824"},{"name":"25474","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25474"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2007-57/advisory/"},{"name":"26374","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26374"},{"name":"37321","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37321"},{"name":"1018623","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1018623"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-07-045/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-08-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2 through SP4 for Windows allow remote attackers to execute arbitrary code via certain long arguments to the (1) RpcAddPrinterDriver, (2) RpcGetPrinterDriverDirectory, and other unspecified RPC requests, aka Novell bug 300870, a different vulnerability than CVE-2006-5854."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","shortName":"flexera"},"references":[{"name":"ADV-2007-3006","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3006"},{"tags":["x_refsource_CONFIRM"],"url":"http://download.novell.com/Download?buildid=VOXNZb-6t_g~"},{"name":"novell-client-nwspool-bo(35824)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35824"},{"name":"25474","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25474"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2007-57/advisory/"},{"name":"26374","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26374"},{"name":"37321","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37321"},{"name":"1018623","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1018623"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-07-045/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"PSIRT-CNA@flexerasoftware.com","ID":"CVE-2007-2954","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2 through SP4 for Windows allow remote attackers to execute arbitrary code via certain long arguments to the (1) RpcAddPrinterDriver, (2) RpcGetPrinterDriverDirectory, and other unspecified RPC requests, aka Novell bug 300870, a different vulnerability than CVE-2006-5854."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2007-3006","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3006"},{"name":"http://download.novell.com/Download?buildid=VOXNZb-6t_g~","refsource":"CONFIRM","url":"http://download.novell.com/Download?buildid=VOXNZb-6t_g~"},{"name":"novell-client-nwspool-bo(35824)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35824"},{"name":"25474","refsource":"BID","url":"http://www.securityfocus.com/bid/25474"},{"name":"http://secunia.com/secunia_research/2007-57/advisory/","refsource":"MISC","url":"http://secunia.com/secunia_research/2007-57/advisory/"},{"name":"26374","refsource":"SECUNIA","url":"http://secunia.com/advisories/26374"},{"name":"37321","refsource":"OSVDB","url":"http://osvdb.org/37321"},{"name":"1018623","refsource":"SECTRACK","url":"http://securitytracker.com/id?1018623"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-07-045/","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-07-045/"}]}}}},"cveMetadata":{"assignerOrgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","assignerShortName":"flexera","cveId":"CVE-2007-2954","datePublished":"2007-08-31T22:00:00.000Z","dateReserved":"2007-05-31T00:00:00.000Z","dateUpdated":"2024-08-07T13:57:54.748Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-08-31 22:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:novell:client:4.91:sp2:*:*:*:*:*:*","matchCriteriaId":"78A17422-1FFE-4942-A6F1-01F99E4D42F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:client:4.91:sp3:*:*:*:*:*:*","matchCriteriaId":"F0CBDEB2-98CF-4C6A-A45A-F5B61803E449"},{"vulnerable":true,"criteria":"cpe:2.3:a:novell:client:4.91:sp4:*:*:*:*:*:*","matchCriteriaId":"EDDFB0E9-EF4C-4E9E-9369-453AF2A8481F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2954","Ordinal":"1","Title":"CVE-2007-2954","CVE":"CVE-2007-2954","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2954","Ordinal":"1","NoteData":"Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2 through SP4 for Windows allow remote attackers to execute arbitrary code via certain long arguments to the (1) RpcAddPrinterDriver, (2) RpcGetPrinterDriverDirectory, and other unspecified RPC requests, aka Novell bug 300870, a different vulnerability than CVE-2006-5854.","Type":"Description","Title":"CVE-2007-2954"},{"CveYear":"2007","CveId":"2954","Ordinal":"2","NoteData":"2007-08-31","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2954","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}