CVE-2008-4478

Multiple integer overflows in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.73 before 8.7.3.10 ftf1, allow remote attackers to execute arbitrary code via a crafted (1) Content-Length header in a SOAP request or (2) Netware Core Protocol opcode 0x0F message, which triggers a heap-based buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
novelledirectory
𝑥
≤ 8.7.3.10
novelledirectory
8.7
novelledirectory
8.7.1
novelledirectory
8.7.1:sp1
novelledirectory
8.7.3
novelledirectory
8.7.3.8
novelledirectory
8.7.3.8_presp9:_presp9
novelledirectory
8.7.3.9
novelledirectory
8.7.3.9
novelledirectory
8.7.3.9
novelledirectory
8.7.3.9
novelledirectory
8.7.3.9
novelledirectory
8.8
novelledirectory
8.8
novelledirectory
8.8
novelledirectory
8.8
novelledirectory
8.8
novelledirectory
8.8.1
novelledirectory
8.8.1
novelledirectory
8.8.1
novelledirectory
8.8.1
novelledirectory
8.8.1
novelledirectory
8.8.2
novelledirectory
8.8.2
novelledirectory
8.8.2
novelledirectory
8.8.2
novelledirectory
8.8.2
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References