cbcvebase.

Novell Edirectory vulnerabilities

50 known vulnerabilities affecting novell/edirectory.

Total CVEs
50
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH13MEDIUM20LOW1

Vulnerabilities

Page 3 of 3
CVE-2014-5212P4MEDIUMCVSS 4.3≤ 8.82014-12-19
CVE-2014-5212 [MEDIUM] CWE-79 CVE-2014-5212: Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory before Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote attackers to inject arbitrary web script or HTML via the rdn parameter.
nvd
CVE-2009-3862P4MEDIUMCVSS 5.0v8.7.3v8.7.3.8+4 more2009-11-04
CVE-2009-3862 [MEDIUM] CWE-287 CVE-2009-3862: The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value.
nvd
CVE-2006-5479P4MEDIUMCVSS 5.0≤ 8.7.3.8v8.0+7 more2006-10-24
CVE-2006-5479 [MEDIUM] CVE-2006-5479: The NCP Engine in Novell eDirectory before 8.7.3.8 FTF1 allows remote attackers to cause an unspecif The NCP Engine in Novell eDirectory before 8.7.3.8 FTF1 allows remote attackers to cause an unspecified denial of service via a certain "NCP Fragment."
nvd
CVE-2014-5213P4MEDIUMCVSS 4.0≤ 8.82014-12-19
CVE-2014-5213 [MEDIUM] CWE-200 CVE-2014-5213: nds/files/opt/novell/eDirectory/lib64/ndsimon/public/images in iMonitor in Novell eDirectory before nds/files/opt/novell/eDirectory/lib64/ndsimon/public/images in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote authenticated users to obtain sensitive information from process memory via a direct request.
nvd
CVE-2008-0925P4MEDIUMCVSS 4.3v8.7.3.9v8.8+2 more2008-06-18
CVE-2008-0925 [MEDIUM] CWE-79 CVE-2008-0925: Cross-site scripting (XSS) vulnerability in the iMonitor interface in Novell eDirectory 8.7.3.x befo Cross-site scripting (XSS) vulnerability in the iMonitor interface in Novell eDirectory 8.7.3.x before 8.7.3 sp10, and 8.8.x before 8.8.2 ftf2, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters that are used within "error messages of the HTTP stack."
nvd
CVE-2008-5093P4MEDIUMCVSS 4.3≤ 8.8v8.0+13 more2008-11-14
CVE-2008-5093 [MEDIUM] CWE-79 CVE-2008-5093: Cross-site scripting (XSS) vulnerability in the HTTP Protocol Stack (HTTPSTK) in Novell eDirectory b Cross-site scripting (XSS) vulnerability in the HTTP Protocol Stack (HTTPSTK) in Novell eDirectory before 8.8 SP3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
nvd
CVE-2005-1729P4MEDIUMCVSS 5.0v8.7.32005-06-12
CVE-2005-1729 [MEDIUM] CVE-2005-1729: Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via a URL containing an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1.
nvd
CVE-2006-5813P4MEDIUMCVSS 5.0v8.82006-11-08
CVE-2006-5813 [MEDIUM] CVE-2006-5813: Unspecified vulnerability in Novell eDirectory 8.8 allows attackers to cause a denial of service, as Unspecified vulnerability in Novell eDirectory 8.8 allows attackers to cause a denial of service, as demonstrated by vd_novell3.pm, a "Novell eDirectory 8.8 DoS." NOTE: As of 20061108, this disclosure has no actionable information. However, since it is from a reliable researcher, it is being assigned a CVE identifier for tracking purposes.
nvd
CVE-2006-4185P4MEDIUMCVSS 4.9v8.7v8.7.1+2 more2006-08-17
CVE-2006-4185 [MEDIUM] CVE-2006-4185: Unspecified vulnerability in the NCPENGINE in Novell eDirectory 8.7.3.8 allows local users to cause Unspecified vulnerability in the NCPENGINE in Novell eDirectory 8.7.3.8 allows local users to cause a denial of service (CPU consumption) via unspecified vectors, as originally demonstrated using a Nessus scan.
nvd
CVE-2006-4186P4LOWCVSS 2.1v8.7.3.82006-08-17
CVE-2006-4186 [LOW] CVE-2006-4186: The iManager in eMBoxClient.jar in Novell eDirectory 8.7.3.8 writes passwords in plaintext to a log The iManager in eMBoxClient.jar in Novell eDirectory 8.7.3.8 writes passwords in plaintext to a log file, which allows local users to obtain passwords by reading the file.
nvd
Novell Edirectory vulnerabilities | cvebase