← Vulnerability feed

Vulnerability record · CVE-2006-0998 · published 23 March 2006

CVE-2006-0998: Novell open enterprise server vulnerability

Novell · Open Enterprise Server

The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) sometimes selects a weak cipher instead of an available stronger cipher, which makes it easier for remote attackers to sniff and decrypt an SSL protected session.

5.0 CVSS 2.0 Medium EPSS 3.2% · top 12.2%
5.0CVSS 2.0 base score
3.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) sometimes selects a weak cipher instead of an available stronger cipher, which makes it easier for remote attackers to sniff and decrypt an SSL protected session.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-0998 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed10.0CVE-2014-0609Novell open enterprise server vulnerabilityUnspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 SP2 before Scheduled Maintena…EPSS 2.2%10.0CVE-2014-0598Novell open enterprise server path traversal vulnerabilityDirectory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified imp…EPSS 2.5%10.0CVE-2010-4227Novell netware memory buffer overflow vulnerabilityThe xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arb…EPSS 17%10.0CVE-2010-2351Novell netware memory buffer overflow vulnerabilityStack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbit…EPSS 16%10.0CVE-2003-1595Novell netware ftp server permissions and access controls vulnerabilityNWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly perform "intruder detection," which has unspecified impact and at…EPSS 1.7%10.0CVE-2006-0736Novell linux desktop vulnerabilityStack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote …EPSS 7.1%

Source: NIST National Vulnerability Database (record CVE-2006-0998), CISA KEV, FIRST EPSS (scores of 2026-10-08). This page is refreshed as NVD updates the record.