Skip to main content

Vendor/product archive

novell / edirectory CVEs

Beta · best-effort

49 CVEs tagged to novell / edirectory16 Critical, 11 High, 21 Medium, 1 Low, 0 Unrated.

CVE-2017-9277

Published Mar 2, 2018

The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA.

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9267

Published Mar 2, 2018

In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9168

Published Mar 23, 2017

A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9167

Published Mar 23, 2017

NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5747

Published Mar 23, 2017

A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-5213

Published Dec 19, 2014

nds/files/opt/novell/eDirectory/lib64/ndsimon/public/images in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote authenticated users to obtain sensitive informati…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5212

Published Dec 19, 2014

Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4327

Published Feb 10, 2011

Unspecified vulnerability in the NCP service in Novell eDirectory 8.8.5 before 8.8.5.6 and 8.8.6 before 8.8.6.2 allows remote attackers to cause a denial of service (hang) via a m…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4655

Published Feb 26, 2010

The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4654

Published Feb 26, 2010

Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute arbitrary code via long sadminpwd and verifyp…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4653

Published Feb 26, 2010

Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to cause a denial of service (dhost.exe crash) and possi…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0666

Published Feb 19, 2010

Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and earlier allows remote attackers to cause a denial of service (crash) via unknown a crafted SOAP request…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0895

Published Dec 3, 2009

Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containin…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3862

Published Nov 4, 2009

The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote at…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2457

Published Jul 14, 2009

The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (crash) via a malformed bind LDAP packet.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2456

Published Jul 14, 2009

The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (ndsd core dump) via an LDAP request containing multiple . (dot) wil…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0192

Published Jul 14, 2009

Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP re…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5094

Published Nov 14, 2008

Heap-based buffer overflow in the NDS Service in Novell eDirectory before 8.8 SP3 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5093

Published Nov 14, 2008

Cross-site scripting (XSS) vulnerability in the HTTP Protocol Stack (HTTPSTK) in Novell eDirectory before 8.8 SP3 allows remote attackers to inject arbitrary web script or HTML vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5092

Published Nov 14, 2008

Heap-based buffer overflows in Novell eDirectory HTTP protocol stack (HTTPSTK) before 8.8 SP3 have unknown impact and attack vectors related to the (1) HTTP language header and (2…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5091

Published Nov 14, 2008

Buffer overflow in the LDAP Service in Novell eDirectory 8.7.3 before SP10a and 8.8 before SP3 allows attackers to cause a denial of service (application crash) via vectors involv…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5038

Published Nov 12, 2008

Use-after-free vulnerability in the NetWare Core Protocol (NCP) feature in Novell eDirectory 8.7.3 SP10 before 8.7.3 SP10 FTF1 and 8.8 SP2 for Windows allows remote attackers to c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4480

Published Oct 14, 2008

Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.x before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a crafted Netw…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4479

Published Oct 14, 2008

Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a SOAP request…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 49 CVEsPage 1 of 2