10

CVE-2008-4478

Multiple integer overflows in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.73 before 8.7.3.10 ftf1, allow remote attackers to execute arbitrary code via a crafted (1) Content-Length header in a SOAP request or (2) Netware Core Protocol opcode 0x0F message, which triggers a heap-based buffer overflow.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NovellEdirectory Version <= 8.7.3.10
NovellEdirectory Version8.7
NovellEdirectory Version8.7.1
NovellEdirectory Version8.7.1 Updatesp1
NovellEdirectory Version8.7.3
NovellEdirectory Version8.7.3.8
NovellEdirectory Version8.7.3.8_presp9
NovellEdirectory Version8.7.3.9
NovellEdirectory Version8.7.3.9 Editionlinux
NovellEdirectory Version8.7.3.9 Editionsolaris
NovellEdirectory Version8.7.3.9 Editionwindows_2000
NovellEdirectory Version8.7.3.9 Editionwindows_2003
NovellEdirectory Version8.8
NovellEdirectory Version8.8 Editionlinux
NovellEdirectory Version8.8 Editionsolaris
NovellEdirectory Version8.8 Editionwindows_2000
NovellEdirectory Version8.8 Editionwindows_2003
NovellEdirectory Version8.8.1
NovellEdirectory Version8.8.1 Editionlinux
NovellEdirectory Version8.8.1 Editionsolaris
NovellEdirectory Version8.8.1 Editionwindows_2000
NovellEdirectory Version8.8.1 Editionwindows_2003
NovellEdirectory Version8.8.2
NovellEdirectory Version8.8.2 Editionlinux
NovellEdirectory Version8.8.2 Editionsolaris
NovellEdirectory Version8.8.2 Editionwindows_2000
NovellEdirectory Version8.8.2 Editionwindows_2003
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 65.89% 0.983
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C