← Vulnerability feed

Vulnerability record · CVE-2005-3659 · published 31 December 2005

CVE-2005-3659: Emc legato networker vulnerability

Emc · Legato Networker

nsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allows remote attackers to cause a denial of service (nsrd service crash) via a malformed RPC request to RPC program number 390109, which triggers a null dereference.

5.0 CVSS 2.0 Medium EPSS 2.5% · top 15.9% CWE-399 · CWE-399
5.0CVSS 2.0 base score
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

nsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allows remote attackers to cause a denial of service (nsrd service crash) via a malformed RPC request to RPC program number 390109, which triggers a null dereference.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.legato.com/pub/NetWorker/Updates/LGTpa83990/README.TXT Patch
http://secunia.com/advisories/18495 ExploitPatchVendor Advisory
http://secunia.com/advisories/18615 PatchVendor Advisory
http://securitytracker.com/id?1015500 Patch
http://securitytracker.com/id?1015545 Patch
http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102148-1
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=375 ExploitPatch
http://www.legato.com/support/websupport/product_alerts/011606_NW.htm Patch
http://www.securityfocus.com/bid/16275 Patch
http://www.vupen.com/english/advisories/2006/0233 Vendor Advisory
http://www.vupen.com/english/advisories/2006/0343 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/24173
ftp://ftp.legato.com/pub/NetWorker/Updates/LGTpa83990/README.TXT Patch
http://secunia.com/advisories/18495 ExploitPatchVendor Advisory
http://secunia.com/advisories/18615 PatchVendor Advisory
http://securitytracker.com/id?1015500 Patch
http://securitytracker.com/id?1015545 Patch
http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102148-1
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=375 ExploitPatch
http://www.legato.com/support/websupport/product_alerts/011606_NW.htm Patch
http://www.securityfocus.com/bid/16275 Patch
http://www.vupen.com/english/advisories/2006/0233 Vendor Advisory
http://www.vupen.com/english/advisories/2006/0343 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/24173

Track CVE-2005-3659 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-2754Ibm informix dynamic server vulnerabilityInteger signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe)…EPSS 40%9.3CVE-2007-3618Emc legato networker vulnerabilityStack-based buffer overflow in the NetWorker Remote Exec Service (nsrexecd.exe) in EMC Software NetWorker 7.x.x allows remote attackers to execute ar…EPSS 7.1%7.5CVE-2005-3658Emc legato networker memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Sols…EPSS 5.2%7.5CVE-2005-0357Emc legato networker vulnerabilityEMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies …EPSS 4.5%7.5CVE-2005-0358Emc legato networker vulnerabilityEMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which…EPSS 4.6%6.4CVE-2005-0359Emc legato networker vulnerabilityThe Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict acce…EPSS 4.3%8.8CVE-2010-0806Microsoft Internet Explorer Peer Objects use-after-free allows remote code executionInternet Explorer 6, 6 SP1 and 7 contain a use-after-free in the Peer Objects component (iepeers.dll), where an object is accessed after deletion, le…KEVEPSS 82%analysed5.9CVE-2018-0180Cisco IOS Login Block feature denial-of-service via crafted login attemptsMultiple flaws in the Login Enhancements (Login Block) feature of Cisco IOS Software let an unauthenticated remote attacker trigger a reload of the d…KEVEPSS 4.9%analysed

Source: NIST National Vulnerability Database (record CVE-2005-3659), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.