10

CVE-2009-0895

Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containing a large integer value that triggers a heap-based buffer overflow.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NovellEdirectory Version8.7.3
NovellEdirectory Version8.7.3 Updatesp10
NovellEdirectory Version8.7.3 Updatesp10 Editionftf1
NovellEdirectory Version8.7.3 Updatesp10_b
NovellEdirectory Version8.7.3 Updatesp3
NovellEdirectory Version8.7.3 Updatesp3 Editionftf1
NovellEdirectory Version8.7.3 Updatesp4
NovellEdirectory Version8.7.3 Updatesp4 Editionftf1
NovellEdirectory Version8.7.3 Updatesp5
NovellEdirectory Version8.7.3 Updatesp5 Editionftf1
NovellEdirectory Version8.7.3.8
NovellEdirectory Version8.7.3.9
NovellEdirectory Version8.7.3.10
NovellEdirectory Version8.8
NovellEdirectory Version8.8 Updatesp1
NovellEdirectory Version8.8 Updatesp2
NovellEdirectory Version8.8 Updatesp3 Editionftf3
NovellEdirectory Version8.8 Updatesp4
NovellEdirectory Version8.8.1
NovellEdirectory Version8.8.2
NovellEdirectory Version8.8.2 Editionftf1
NovellEdirectory Version8.8.5 Editionftf1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 26.23% 0.958
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C