Show filters
33 Total Results
Displaying 1-10 of 33
Sort by:
Attacker Value
Unknown

Fix for NetIQ shell code upload

Disclosure Date: March 02, 2018 (last updated November 08, 2023)
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
0
Attacker Value
Unknown

CVE-2012-0430

Disclosure Date: December 25, 2012 (last updated October 05, 2023)
Unspecified vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote attackers to obtain an administrator cookie and bypass authorization checks via unknown vectors.
0
Attacker Value
Unknown

CVE-2012-0432

Disclosure Date: December 25, 2012 (last updated October 05, 2023)
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2012-0429

Disclosure Date: December 25, 2012 (last updated October 05, 2023)
dhost in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote authenticated users to cause a denial of service (daemon crash) via crafted characters in an HTTP request.
0
Attacker Value
Unknown

CVE-2012-0428

Disclosure Date: December 25, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-4327

Disclosure Date: February 10, 2011 (last updated October 04, 2023)
Unspecified vulnerability in the NCP service in Novell eDirectory 8.8.5 before 8.8.5.6 and 8.8.6 before 8.8.6.2 allows remote attackers to cause a denial of service (hang) via a malformed FileSetLock request to port 524.
0
Attacker Value
Unknown

CVE-2009-4655

Disclosure Date: February 26, 2010 (last updated October 04, 2023)
The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie.
0
Attacker Value
Unknown

CVE-2009-4654

Disclosure Date: February 26, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute arbitrary code via long sadminpwd and verifypwd parameters in a submit action to /dhost/httpstk.
0
Attacker Value
Unknown

CVE-2009-4653

Disclosure Date: February 26, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to cause a denial of service (dhost.exe crash) and possibly execute arbitrary code via a long string to /dhost/modules?I:.
0
Attacker Value
Unknown

CVE-2010-0666

Disclosure Date: February 19, 2010 (last updated October 04, 2023)
Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and earlier allows remote attackers to cause a denial of service (crash) via unknown a crafted SOAP request, a different issue than CVE-2008-0926.
0