Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 2.2% | — | Microfocus Edirectory | 25/12/2012 | 16/6/2026 | Unspecified vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote attackers to obtain an administrator cookie and bypass authorization checks via unknown vectors. | |
| Modificada | Media (4) | 1.9% | — | Microfocus Edirectory | 25/12/2012 | 16/6/2026 | dhost in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote authenticated users to cause a denial of service (daemon crash) via crafted characters in an HTTP request. | |
| Modificada | Media (4.3) | 1.8% | — | Microfocus Edirectory | 25/12/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Harmistechnology COM Jedirectory | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in the JExtensions JE Directory (com_jedirectory) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php. | |
| Modificada | Media (5) | 2.9% | — | Novell Edirectory | 10/2/2011 | 16/6/2026 | Unspecified vulnerability in the NCP service in Novell eDirectory 8.8.5 before 8.8.5.6 and 8.8.6 before 8.8.6.2 allows remote attackers to cause a denial of service (hang) via a malformed FileSetLock request to port 524. | |
| Modificada | Alta (7.5) | 51% | 💥 Exploit | Novell Edirectory | 26/2/2010 | 16/6/2026 | The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie. | |
| Modificada | Alta (9) | 6.7% | 💥 Exploit | Novell Edirectory | 26/2/2010 | 16/6/2026 | Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute arbitrary code via long sadminpwd and verifypwd parameters in a submit action to /dhost/httpstk. | |
| Modificada | Alta (9) | 13% | 💥 Exploit | Novell Edirectory | 26/2/2010 | 16/6/2026 | Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to cause a denial of service (dhost.exe crash) and possibly execute arbitrary code via a long string to /dhost/modules?I:. | |
| Modificada | Media (5) | 2.3% | — | Novell Edirectory | 19/2/2010 | 16/6/2026 | Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and earlier allows remote attackers to cause a denial of service (crash) via unknown a crafted SOAP request, a different issue than CVE-2008-0926. | |
| Modificada | Alta (10) | 6.8% | — | Novell Edirectory | 3/12/2009 | 16/6/2026 | Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containing a large integer value that triggers a heap-based buffer overflow. | |
| Modificada | Media (5) | 2.3% | — | Novell Edirectory | 4/11/2009 | 16/6/2026 | The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value. | |
| Modificada | Media (5) | 2.4% | — | Novell Edirectory | 14/7/2009 | 16/6/2026 | The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (crash) via a malformed bind LDAP packet. | |
| Modificada | Media (5) | 2.5% | — | Novell Edirectory | 14/7/2009 | 16/6/2026 | The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (ndsd core dump) via an LDAP request containing multiple . (dot) wildcard characters in the Relative Distinguished Name (RDN). | |
| Modificada | Media (5) | 12% | 💥 Exploit | Novell Edirectory | 14/7/2009 | 16/6/2026 | Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP request with a crafted Accept-Language header, which triggers a stack-based buffer overflow. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Audioarticledirectory Audio Article Directory | 9/7/2009 | 16/6/2026 | Directory traversal vulnerability in download.php in Audio Article Directory allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Freedirectoryscript Free Directory Script | 26/2/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in init.php in Free Directory Script 1.1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the API_HOME_DIR parameter. | |
| Modificada | Alta (10) | 1.7% | — | Novell Edirectory | 14/11/2008 | 16/6/2026 | Heap-based buffer overflow in the NDS Service in Novell eDirectory before 8.8 SP3 has unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Novell Edirectory | 14/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the HTTP Protocol Stack (HTTPSTK) in Novell eDirectory before 8.8 SP3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Alta (10) | 1.7% | — | Novell Edirectory | 14/11/2008 | 16/6/2026 | Heap-based buffer overflows in Novell eDirectory HTTP protocol stack (HTTPSTK) before 8.8 SP3 have unknown impact and attack vectors related to the (1) HTTP language header and (2) HTTP content-length header. | |
| Modificada | Alta (10) | 2.1% | — | Novell Edirectory | 14/11/2008 | 16/6/2026 | Buffer overflow in the LDAP Service in Novell eDirectory 8.7.3 before SP10a and 8.8 before SP3 allows attackers to cause a denial of service (application crash) via vectors involving an "invalid extensibleMatch filter." | |
| Modificada | Crítica (9.8) | 6.2% | — | Novell Edirectory | 12/11/2008 | 16/6/2026 | Use-after-free vulnerability in the NetWare Core Protocol (NCP) feature in Novell eDirectory 8.7.3 SP10 before 8.7.3 SP10 FTF1 and 8.8 SP2 for Windows allows remote attackers to cause a denial of service and possibly execute arbitrary code via a sequence of "Get NCP Extension Information By Name" requests that cause… | |
| Modificada | Alta (10) | 11% | — | Novell Edirectory | 14/10/2008 | 16/6/2026 | Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.x before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a crafted Netware Core Protocol opcode 0x24 message that triggers a calculation error that under-allocates a heap buffer. | |
| Modificada | Alta (10) | 10% | — | Novell Edirectory | 14/10/2008 | 16/6/2026 | Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a SOAP request with a long Accept-Language header. | |
| Modificada | Alta (10) | 9.8% | — | Novell Edirectory | 14/10/2008 | 16/6/2026 | Multiple integer overflows in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.73 before 8.7.3.10 ftf1, allow remote attackers to execute arbitrary code via a crafted (1) Content-Length header in a SOAP request or (2) Netware Core Protocol opcode 0x0F message, which triggers a heap-based buffer overflow. | |
| Modificada | Baja (2.1) | 0.44% | — | Hpsi Acf2 ConnectorHpsi Active Directory ConnectorHpsi Bidir Dirx ConnectorHpsi Edirectory Connector+7 | 11/9/2008 | 16/6/2026 | Unspecified vulnerability in HP OpenView Select Identity (HPSI) Connectors on Windows, as used in HPSI Active Directory Connector 2.30 and earlier, HPSI SunOne Connector 1.14 and earlier, HPSI eDirectory Connector 1.12 and earlier, HPSI eTrust Connector 1.02 and earlier, HPSI OID Connector 1.02 and earlier, HPSI IBM… |