← Vulnerability feed

Vulnerability record · CVE-2007-5767 · published 2 November 2007

CVE-2007-5767: Novell bordermanager memory buffer overflow vulnerability

Novell · Bordermanager

Heap-based buffer overflow in the Client Trust application (clntrust.exe) in Novell BorderManager 3.8 before Update 1.5 allows remote attackers to execute arbitrary code via a validation request in which the Novell tree name is not properly delimited with a wide-character backslash or NULL character.

10.0 CVSS 2.0 High EPSS 6.8% · top 6.3% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
6.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the Client Trust application (clntrust.exe) in Novell BorderManager 3.8 before Update 1.5 allows remote attackers to execute arbitrary code via a validation request in which the Novell tree name is not properly delimited with a wide-character backslash or NULL character.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-5767 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2006-7155Novell bordermanager vulnerabilityNovell BorderManager 3.8 SP4 generates the same ISAKMP cookies for the same source IP and port number during the same day, which allows remote attack…EPSS 1.7%7.5CVE-2000-0651Novell bordermanager vulnerabilityThe ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to…EPSS 1.8%5.0CVE-2006-5286Novell bordermanager vulnerabilityUnspecified vulnerability in IKE.NLM in Novell BorderManager 3.8 allows attackers to cause a denial of service (crash) via unknown attack vectors rel…EPSS 1.5%5.0CVE-2006-1218Novell bordermanager vulnerabilityUnspecified vulnerability in the HTTP proxy in Novell BorderManager 3.8 and earlier allows remote attackers to cause a denial of service (CPU consump…EPSS 1.6%5.0CVE-2004-1457Novell bordermanager vulnerabilityThe Virtual Private Network (VPN) capability in Novell Bordermanager 3.8 allows remote attackers to cause a denial of service (ABEND in IKE.NLM) via …EPSS 2.1%5.0CVE-2002-0779Novell bordermanager vulnerabilityFTP proxy server for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service (network connectivity loss) via a connection…EPSS 1.7%5.0CVE-2002-0780Novell bordermanager vulnerabilityIP/IPX gateway for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a connection to port 8225 with a large amo…EPSS 1.7%5.0CVE-2002-0781Novell bordermanager vulnerabilityRTSP proxy for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a GET request to port 9090 followed by a serie…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2007-5767), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.