Vulnerabilities > Novell > Edirectory > 8.7.3.8.presp9

DATE CVE VULNERABILITY TITLE RISK
2010-02-19 CVE-2010-0666 Unspecified vulnerability in Novell Edirectory
Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and earlier allows remote attackers to cause a denial of service (crash) via unknown a crafted SOAP request, a different issue than CVE-2008-0926.
network
low complexity
novell
5.0
2008-11-14 CVE-2008-5094 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Edirectory
Heap-based buffer overflow in the NDS Service in Novell eDirectory before 8.8 SP3 has unknown impact and attack vectors.
network
low complexity
novell CWE-119
critical
10.0
2008-11-14 CVE-2008-5093 Cross-Site Scripting vulnerability in Novell Edirectory
Cross-site scripting (XSS) vulnerability in the HTTP Protocol Stack (HTTPSTK) in Novell eDirectory before 8.8 SP3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
novell CWE-79
4.3
2008-11-14 CVE-2008-5092 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Edirectory
Heap-based buffer overflows in Novell eDirectory HTTP protocol stack (HTTPSTK) before 8.8 SP3 have unknown impact and attack vectors related to the (1) HTTP language header and (2) HTTP content-length header.
network
low complexity
novell CWE-119
critical
10.0
2008-11-14 CVE-2008-5091 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Edirectory
Buffer overflow in the LDAP Service in Novell eDirectory 8.7.3 before SP10a and 8.8 before SP3 allows attackers to cause a denial of service (application crash) via vectors involving an "invalid extensibleMatch filter."
network
low complexity
novell CWE-119
critical
10.0
2008-10-14 CVE-2008-4478 Numeric Errors vulnerability in Novell Edirectory
Multiple integer overflows in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.73 before 8.7.3.10 ftf1, allow remote attackers to execute arbitrary code via a crafted (1) Content-Length header in a SOAP request or (2) Netware Core Protocol opcode 0x0F message, which triggers a heap-based buffer overflow.
network
low complexity
novell CWE-189
critical
10.0
2008-03-28 CVE-2008-0926 Improper Authentication vulnerability in Novell Edirectory
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files.
network
low complexity
novell CWE-287
7.5
2006-10-24 CVE-2006-5478 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Edirectory
Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allow remote attackers to execute arbitrary code via (1) a long HTTP Host header, which triggers an overflow in the BuildRedirectURL function; or vectors related to a username containing a .
network
low complexity
novell CWE-119
7.5