← Vulnerability feed

Vulnerability record · CVE-2013-7441 · published 29 May 2015

CVE-2013-7441: Wouter verhelst nbd vulnerability

WWouter Verhelst · Nbd

The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.

7.8 CVSS 2.0 High EPSS 3.6% · top 10.8% CWE-399 · CWE-399
7.8CVSS 2.0 base score
3.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
17 Jun 2026Last modified by NVD

Description

The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-7441 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2015-0847Canonical ubuntu linux vulnerabilitynbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a denial of se…EPSS 3.1%7.5CVE-2013-6410Wouter verhelst nbd permissions and access controls vulnerabilitynbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended acces…EPSS 2.5%7.5CVE-2011-0530Wouter verhelst nbd memory buffer overflow vulnerabilityBuffer overflow in the mainloop function in nbd-server.c in the server in Network Block Device (nbd) before 2.9.20 might allow remote attackers to ex…EPSS 5.3%7.5CVE-2005-3534Wouter verhelst nbd memory buffer overflow vulnerabilityBuffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary cod…EPSS 6.0%5.0CVE-2011-1925Wouter verhelst nbd vulnerabilitynbd-server.c in Network Block Device (nbd-server) 2.9.21 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by…EPSS 2.5%8.8CVE-2010-0806Microsoft Internet Explorer Peer Objects use-after-free allows remote code executionInternet Explorer 6, 6 SP1 and 7 contain a use-after-free in the Peer Objects component (iepeers.dll), where an object is accessed after deletion, le…KEVEPSS 82%analysed5.9CVE-2018-0180Cisco IOS Login Block feature denial-of-service via crafted login attemptsMultiple flaws in the Login Enhancements (Login Block) feature of Cisco IOS Software let an unauthenticated remote attacker trigger a reload of the d…KEVEPSS 4.9%analysed5.9CVE-2018-0179Cisco IOS Login Block feature denial-of-service flawMultiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software let an unauthenticated, remote attacker trigger a relo…KEVEPSS 4.9%analysed

Source: NIST National Vulnerability Database (record CVE-2013-7441), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.