CVE-2008-0926
- EPSS 65.87%
- Veröffentlicht 28.03.2008 18:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of s...
CVE-2008-0924
- EPSS 3.89%
- Veröffentlicht 28.03.2008 18:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the DoLBURPRequest function in libnldap in ndsd in Novell eDirectory 8.7.3.9 and earlier, and 8.8.1 and earlier in the 8.8.x series, allows remote attackers to cause a denial of service (daemon crash or CPU consumption)...
CVE-2006-4520
- EPSS 8.26%
- Veröffentlicht 30.04.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
ncp in Novell eDirectory before 8.7.3 SP9, and 8.8.x before 8.8.1 FTF2, does not properly handle NCP fragments with a negative length, which allows remote attackers to cause a denial of service (daemon crash) when the heap is written to a log file.
CVE-2006-5814
- EPSS 2.39%
- Veröffentlicht 08.11.2006 23:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Novell eDirectory allows remote attackers to execute arbitrary code, as demonstrated by vd_novell.pm, a "Novell eDirectory remote exploit." NOTE: As of 20061108, this disclosure has no actionable information. However, sin...
- EPSS 0.21%
- Veröffentlicht 08.11.2006 23:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Novell eDirectory 8.8 allows attackers to cause a denial of service, as demonstrated by vd_novell3.pm, a "Novell eDirectory 8.8 DoS." NOTE: As of 20061108, this disclosure has no actionable information. However, since it ...
- EPSS 3.28%
- Veröffentlicht 04.11.2006 00:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The BerDecodeLoginDataRequest function in the libnmasldap.so NMAS module in Novell eDirectory 8.8 and 8.8.1 before the Security Services 2.0.3 patch does not properly increment a pointer when handling certain input, which allows remote attackers to c...
CVE-2006-5478
- EPSS 90.7%
- Veröffentlicht 24.10.2006 20:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allow remote attackers to execute arbitrary code via (1) a long HTTP Host header, which triggers an overf...
CVE-2006-4177
- EPSS 9.58%
- Veröffentlicht 24.10.2006 20:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in the NCP engine in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted NCP over IP packet that causes NCP to read more data than intended.
- EPSS 0.57%
- Veröffentlicht 24.10.2006 20:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The NCP Engine in Novell eDirectory before 8.7.3.8 FTF1 allows remote attackers to cause an unspecified denial of service via a certain "NCP Fragment."
- EPSS 37.86%
- Veröffentlicht 24.10.2006 19:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The evtFilteredMonitorEventsRequest function in the LDAP service in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted request containing a value that is larger than the number of objects transmitted, ...