Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2008-1809
Disclosure Date: July 14, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in Novell eDirectory 8.7.3 before 8.7.3.10b, and 8.8 before 8.8.2 FTF2, allows remote attackers to execute arbitrary code via an LDAP search request containing "NULL search parameters."
0
Attacker Value
Unknown
CVE-2008-0925
Disclosure Date: June 18, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the iMonitor interface in Novell eDirectory 8.7.3.x before 8.7.3 sp10, and 8.8.x before 8.8.2 ftf2, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters that are used within "error messages of the HTTP stack."
0
Attacker Value
Unknown
CVE-2008-0926
Disclosure Date: March 28, 2008 (last updated October 04, 2023)
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.
0
Attacker Value
Unknown
CVE-2006-5478
Disclosure Date: October 24, 2006 (last updated October 04, 2023)
Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allow remote attackers to execute arbitrary code via (1) a long HTTP Host header, which triggers an overflow in the BuildRedirectURL function; or vectors related to a username containing a . (dot) character in the (2) SMTP, (3) POP, (4) IMAP, (5) HTTP, or (6) Networked Messaging Application Protocol (NMAP) Netmail services.
0
Attacker Value
Unknown
CVE-2006-5479
Disclosure Date: October 24, 2006 (last updated October 04, 2023)
The NCP Engine in Novell eDirectory before 8.7.3.8 FTF1 allows remote attackers to cause an unspecified denial of service via a certain "NCP Fragment."
0
Attacker Value
Unknown
CVE-2006-4186
Disclosure Date: August 17, 2006 (last updated October 04, 2023)
The iManager in eMBoxClient.jar in Novell eDirectory 8.7.3.8 writes passwords in plaintext to a log file, which allows local users to obtain passwords by reading the file.
0
Attacker Value
Unknown
CVE-2006-4185
Disclosure Date: August 17, 2006 (last updated October 04, 2023)
Unspecified vulnerability in the NCPENGINE in Novell eDirectory 8.7.3.8 allows local users to cause a denial of service (CPU consumption) via unspecified vectors, as originally demonstrated using a Nessus scan.
0
Attacker Value
Unknown
CVE-2005-2551
Disclosure Date: August 12, 2005 (last updated February 22, 2025)
Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors.
0
Attacker Value
Unknown
CVE-2005-1729
Disclosure Date: June 12, 2005 (last updated February 22, 2025)
Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via a URL containing an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1.
0