cbcvebase.

Novell Edirectory vulnerabilities

50 known vulnerabilities affecting novell/edirectory.

Total CVEs
50
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH13MEDIUM20LOW1

Vulnerabilities

Page 2 of 3
CVE-2017-9277P3HIGHCVSS 7.5≤ 9.0v9.0+1 more2018-03-02
CVE-2017-9277 [HIGH] CVE-2017-9277: The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authe The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA.
nvd
CVE-2008-5094P3CRITICALCVSS 10.0≤ 8.8v8.0+13 more2008-11-14
CVE-2008-5094 [CRITICAL] CWE-119 CVE-2008-5094: Heap-based buffer overflow in the NDS Service in Novell eDirectory before 8.8 SP3 has unknown impact Heap-based buffer overflow in the NDS Service in Novell eDirectory before 8.8 SP3 has unknown impact and attack vectors.
nvd
CVE-2016-9167P3HIGHCVSS 7.5≤ 9.0.12017-03-23
CVE-2016-9167 [HIGH] CWE-264 CVE-2016-9167: NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition bound NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtered by an ACL.
nvd
CVE-2008-0924P3MEDIUMCVSS 6.8≥ 8.7, ≤ 8.7.3.9≥ 8.8, ≤ 8.8.12008-03-28
CVE-2008-0924 [MEDIUM] CWE-119 CVE-2008-0924: Stack-based buffer overflow in the DoLBURPRequest function in libnldap in ndsd in Novell eDirectory Stack-based buffer overflow in the DoLBURPRequest function in libnldap in ndsd in Novell eDirectory 8.7.3.9 and earlier, and 8.8.1 and earlier in the 8.8.x series, allows remote attackers to cause a denial of service (daemon crash or CPU consumption) or execute arbitrary code via a long delRequest LDAP Extended Request message, probably involving a lon
nvd
CVE-2017-9267P3HIGHCVSS 7.5fixed in 9.0.3.1≥ unspecified, < 9.0.3.12018-03-02
CVE-2017-9267 [HIGH] CWE-757 CVE-2017-9267: In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restriction In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations.
nvd
CVE-2004-0079P4HIGHCVSS 7.5v8.0v8.5+5 more2004-11-23
CVE-2004-0079 [HIGH] CWE-476 CVE-2004-0079: The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
nvd
CVE-2017-5186P4HIGHCVSS 7.5≤ 8.82017-04-27
CVE-2017-5186 [HIGH] CWE-327 CVE-2017-5186: Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x b Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.
nvd
CVE-2008-5091P4CRITICALCVSS 10.0≤ 8.8v8.0+14 more2008-11-14
CVE-2008-5091 [CRITICAL] CWE-119 CVE-2008-5091: Buffer overflow in the LDAP Service in Novell eDirectory 8.7.3 before SP10a and 8.8 before SP3 allow Buffer overflow in the LDAP Service in Novell eDirectory 8.7.3 before SP10a and 8.8 before SP3 allows attackers to cause a denial of service (application crash) via vectors involving an "invalid extensibleMatch filter."
nvd
CVE-2016-9168P4MEDIUMCVSS 6.5≤ 9.0.12017-03-23
CVE-2016-9168 [MEDIUM] CWE-20 CVE-2016-9168: A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0. A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.
nvd
CVE-2006-4520P4HIGHCVSS 7.8≤ 8.7.3.8v8.8+1 more2007-04-30
CVE-2006-4520 [HIGH] CVE-2006-4520: ncp in Novell eDirectory before 8.7.3 SP9, and 8.8.x before 8.8.1 FTF2, does not properly handle NCP ncp in Novell eDirectory before 8.7.3 SP9, and 8.8.x before 8.8.1 FTF2, does not properly handle NCP fragments with a negative length, which allows remote attackers to cause a denial of service (daemon crash) when the heap is written to a log file.
nvd
CVE-2002-1552P4HIGHCVSS 7.5v8.6.2v85.20+2 more2003-03-31
CVE-2002-1552 [HIGH] CVE-2002-1552: Novell eDirectory (eDir) 8.6.2 and Netware 5.1 eDir 85.x allows users with expired passwords to gain Novell eDirectory (eDir) 8.6.2 and Netware 5.1 eDir 85.x allows users with expired passwords to gain inappropriate permissions when logging in from Remote Manager.
nvd
CVE-2004-0112P4MEDIUMCVSS 5.0v8.0v8.5+5 more2004-11-23
CVE-2004-0112 [MEDIUM] CWE-125 CVE-2004-0112: The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
nvd
CVE-2002-2119P4CRITICALCVSS 9.8v8.6.2v8.72002-12-31
CVE-2002-2119 [CRITICAL] CWE-178 CVE-2002-2119: Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote att Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing.
nvd
CVE-2004-0081P4MEDIUMCVSS 5.0v8.0v8.5+5 more2004-11-23
CVE-2004-0081 [MEDIUM] CVE-2004-0081: OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote atta OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
nvd
CVE-2010-4327P4MEDIUMCVSS 5.0v8.8.5v8.8.62011-02-10
CVE-2010-4327 [MEDIUM] CVE-2010-4327: Unspecified vulnerability in the NCP service in Novell eDirectory 8.8.5 before 8.8.5.6 and 8.8.6 bef Unspecified vulnerability in the NCP service in Novell eDirectory 8.8.5 before 8.8.5.6 and 8.8.6 before 8.8.6.2 allows remote attackers to cause a denial of service (hang) via a malformed FileSetLock request to port 524.
nvd
CVE-2006-4521P4MEDIUMCVSS 5.0v8.8v8.8.12006-11-04
CVE-2006-4521 [MEDIUM] CVE-2006-4521: The BerDecodeLoginDataRequest function in the libnmasldap.so NMAS module in Novell eDirectory 8.8 an The BerDecodeLoginDataRequest function in the libnmasldap.so NMAS module in Novell eDirectory 8.8 and 8.8.1 before the Security Services 2.0.3 patch does not properly increment a pointer when handling certain input, which allows remote attackers to cause a denial of service (invalid memory access) via a crafted login request.
nvd
CVE-2009-2456P4MEDIUMCVSS 5.0v8.82009-07-14
CVE-2009-2456 [MEDIUM] CVE-2009-2456: The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (ndsd core dump) via an LDAP request containing multiple . (dot) wildcard characters in the Relative Distinguished Name (RDN).
nvd
CVE-2009-2457P4MEDIUMCVSS 5.0v8.82009-07-14
CVE-2009-2457 [MEDIUM] CWE-94 CVE-2009-2457: The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (crash) via a malformed bind LDAP packet.
nvd
CVE-2008-1777P4MEDIUMCVSS 5.0v8.8.22008-04-14
CVE-2008-1777 [MEDIUM] CWE-399 CVE-2008-1777: The eDirectory Host Environment service (dhost.exe) in Novell eDirectory 8.8.2 allows remote attacke The eDirectory Host Environment service (dhost.exe) in Novell eDirectory 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via a long HTTP HEAD request to TCP port 8028.
nvd
CVE-2010-0666P4MEDIUMCVSS 5.0≤ 8.7.3.10v8.5+10 more2010-02-19
CVE-2010-0666 [MEDIUM] CVE-2010-0666: Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and earlier allows remote at Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and earlier allows remote attackers to cause a denial of service (crash) via unknown a crafted SOAP request, a different issue than CVE-2008-0926.
nvd
Novell Edirectory vulnerabilities | cvebase