Novell Edirectory vulnerabilities

50 known vulnerabilities affecting novell/edirectory.

Total CVEs
50
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH13MEDIUM20LOW1

Vulnerabilities

Page 1 of 3
CVE-2017-9277HIGHCVSS 7.5≤ 9.0v9.0+1 more2018-03-02
CVE-2017-9277 [MEDIUM] CVE-2017-9277: The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authe The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA.
cvelistv5nvd
CVE-2017-9267HIGHCVSS 7.5fixed in 9.0.3.1≥ unspecified, < 9.0.3.12018-03-02
CVE-2017-9267 [MEDIUM] CWE-757 CVE-2017-9267: In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restriction In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations.
cvelistv5nvd
CVE-2017-5186HIGHCVSS 7.5≤ 8.82017-04-27
CVE-2017-5186 [HIGH] CWE-327 CVE-2017-5186: Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x b Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.
nvd
CVE-2016-5747HIGHCVSS 7.5≤ 9.02017-03-23
CVE-2016-5747 [HIGH] CWE-284 CVE-2016-5747: A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDire A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictions by leveraging predictable cookies.
nvd
CVE-2016-9167HIGHCVSS 7.5≤ 9.0.12017-03-23
CVE-2016-9167 [HIGH] CWE-264 CVE-2016-9167: NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition bound NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtered by an ACL.
nvd
CVE-2016-9168MEDIUMCVSS 6.5≤ 9.0.12017-03-23
CVE-2016-9168 [MEDIUM] CWE-20 CVE-2016-9168: A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0. A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.
nvd
CVE-2014-5213MEDIUMCVSS 4.0≤ 8.82014-12-19
CVE-2014-5213 [MEDIUM] CWE-200 CVE-2014-5213: nds/files/opt/novell/eDirectory/lib64/ndsimon/public/images in iMonitor in Novell eDirectory before nds/files/opt/novell/eDirectory/lib64/ndsimon/public/images in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote authenticated users to obtain sensitive information from process memory via a direct request.
nvd
CVE-2014-5212MEDIUMCVSS 4.3≤ 8.82014-12-19
CVE-2014-5212 [MEDIUM] CWE-79 CVE-2014-5212: Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory before Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote attackers to inject arbitrary web script or HTML via the rdn parameter.
nvd
CVE-2010-4327MEDIUMCVSS 5.0v8.8.5v8.8.62011-02-10
CVE-2010-4327 [MEDIUM] CVE-2010-4327: Unspecified vulnerability in the NCP service in Novell eDirectory 8.8.5 before 8.8.5.6 and 8.8.6 bef Unspecified vulnerability in the NCP service in Novell eDirectory 8.8.5 before 8.8.5.6 and 8.8.6 before 8.8.6.2 allows remote attackers to cause a denial of service (hang) via a malformed FileSetLock request to port 524.
nvd
CVE-2009-4653CRITICALCVSS 9.0PoCv8.82010-02-26
CVE-2009-4653 [CRITICAL] CWE-119 CVE-2009-4653: Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remo Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to cause a denial of service (dhost.exe crash) and possibly execute arbitrary code via a long string to /dhost/modules?I:.
nvd
CVE-2009-4654CRITICALCVSS 9.0PoCv8.82010-02-26
CVE-2009-4654 [CRITICAL] CWE-119 CVE-2009-4654: Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remo Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute arbitrary code via long sadminpwd and verifypwd parameters in a submit action to /dhost/httpstk.
nvd
CVE-2009-4655HIGHCVSS 7.5PoCv8.8.52010-02-26
CVE-2009-4655 [HIGH] CWE-310 CVE-2009-4655: The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it e The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie.
nvd
CVE-2010-0666MEDIUMCVSS 5.0≤ 8.7.3.10v8.5+10 more2010-02-19
CVE-2010-0666 [MEDIUM] CVE-2010-0666: Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and earlier allows remote at Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and earlier allows remote attackers to cause a denial of service (crash) via unknown a crafted SOAP request, a different issue than CVE-2008-0926.
nvd
CVE-2009-0895CRITICALCVSS 10.0v8.7.3v8.7.3.8+6 more2009-12-03
CVE-2009-0895 [CRITICAL] CWE-189 CVE-2009-0895: Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows r Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containing a large integer value that triggers a heap-based buffer overflow.
nvd
CVE-2009-3862MEDIUMCVSS 5.0v8.7.3v8.7.3.8+4 more2009-11-04
CVE-2009-3862 [MEDIUM] CWE-287 CVE-2009-3862: The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value.
nvd
CVE-2009-0192MEDIUMCVSS 5.0PoCv8.82009-07-14
CVE-2009-0192 [MEDIUM] CWE-189 CVE-2009-0192: Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP request with a crafted Accept-Language header, which triggers a stack-based buffer overflow.
nvd
CVE-2009-2457MEDIUMCVSS 5.0v8.82009-07-14
CVE-2009-2457 [MEDIUM] CWE-94 CVE-2009-2457: The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (crash) via a malformed bind LDAP packet.
nvd
CVE-2009-2456MEDIUMCVSS 5.0v8.82009-07-14
CVE-2009-2456 [MEDIUM] CVE-2009-2456: The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (ndsd core dump) via an LDAP request containing multiple . (dot) wildcard characters in the Relative Distinguished Name (RDN).
nvd
CVE-2008-5094CRITICALCVSS 10.0≤ 8.8v8.0+13 more2008-11-14
CVE-2008-5094 [CRITICAL] CWE-119 CVE-2008-5094: Heap-based buffer overflow in the NDS Service in Novell eDirectory before 8.8 SP3 has unknown impact Heap-based buffer overflow in the NDS Service in Novell eDirectory before 8.8 SP3 has unknown impact and attack vectors.
nvd
CVE-2008-5091CRITICALCVSS 10.0≤ 8.8v8.0+14 more2008-11-14
CVE-2008-5091 [CRITICAL] CWE-119 CVE-2008-5091: Buffer overflow in the LDAP Service in Novell eDirectory 8.7.3 before SP10a and 8.8 before SP3 allow Buffer overflow in the LDAP Service in Novell eDirectory 8.7.3 before SP10a and 8.8 before SP3 allows attackers to cause a denial of service (application crash) via vectors involving an "invalid extensibleMatch filter."
nvd